Actualités¶
Incus 7.5 est maintenant disponible¶
25 sept. 2026
L’équipe d’Incus est heureuse d’annoncer la sortie d’Incus 7.5 !
Cette nouvelle version apporte une fois encore un ensemble de nouvelles fonctionnalités, tant sur le stockage, le réseau, les clusters, le contrôle d’accès, les conteneurs OCI, que sur les agents. La performance des très grands environnements est également significativement améliorée et un bon nombre de bugs et vulnérabilités de sécurité ont été corrigés.
Comme d’habitude, vous pouvez l’essayer vous-même en ligne : https://linuxcontainers.org/incus/try-it/
NOTE : Le numéro de cette nouvelle version est 7.5.1, puisque le processus de construction de la version 7.5.0 comportait des erreurs et des correctifs ont dû être appliqués.
Correctifs de sécurité¶
Cette version corrige 11 vulnérabilités :
- CVE-2026-85185 (critique) – Arbitrary file deletion and directory placement on host via btrfs subvolume path traversal in optimized backups and migration
- CVE-2026-85526 (critique) – Arbitrary file deletion and directory placement on host via btrfs subvolume path traversal in optimized backups
- GHSA-443p-7392-h4v2 (modérée) – Restricted project can use pull mode migration through clustered refresh
- GHSA-4cph-ccqv-hm3c (critique) – Project restriction bypass for
block.create_optionsvia volume update, copy and move - GHSA-579w-c4rw-c8q3 (critique) – Arbitrary file write on host via symlink in migration stream
- GHSA-hpjh-q53p-f27r (critique) – Arbitrary file write on host via path traversal in instance backup dependent volumes
- GHSA-jh4v-j34r-2mgh (haute) – Project restriction bypass for custom volume copy with omitted source type
- GHSA-mfwv-x733-9446 (modérée) – Authorization bypass lets a restricted client read any operation in another project
- GHSA-mmj7-8rgf-mx2h (haute) – Read of other bucket objects via unsigned header on presigned S3 upload URL
- GHSA-wfvq-qh87-gm4j (modérée) – Incus CLI arbitrary file write via malicious
incus-agentduring recursive file pull - GHSA-x8gj-2q73-qr6j (haute) – Restricted client can read storage bucket keys in the default project
Nouvelles fonctionnalités¶
Réseaux OVN enfants¶
Les réseaux OVN peuvent désormais être créés avec une option parent pointant sur un autre réseau OVN du même projet.
Plutôt que d’obtenir un routeur logique dédidé, les réseaux enfants attachent leur switch logique et leur sous-réseau au routeur logique du parent. Cela permet de router plusieurs sous-réseaux internes avec un seul routeur logique partageant son uplink, ses adresses externes et ses pairs.
stgraber@vorash:~$ incus network create net1 --type=ovn network=UPLINK ipv4.address=192.0.2.1/24
stgraber@vorash:~$ incus network create net2 --type=ovn parent=net1 ipv4.address=198.51.100.1/24
stgraber@vorash:~$ incus launch images:debian/13 c1 --network net2
Un réseau enfant conserve son propre sous-réseau, son DHCP, ses enregistrements DNS, ses ACL et ses ports d’instance. Il peut gérer le NAT de manière indépendante du parent et utiliser ipv4.nat.address et ipv6.nat.address pour traduire les IP vers l’adresse de son choix, permettant d’avoir sur un même routeur un sous-réseau NATé et un autre routé nativement.
Les pairs sont gérés par le réseau parent et couvrent les sous-réseaux de tous les enfants.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/network_ovn/#child-networks
Migration de projet à chaud dans un cluster¶
Une instance en cours d’exécution peut désormais être migrée à chaud vers un projet différent sur un autre membre du cluster, en combinant --target-project et --target.
stgraber@vorash:~$ incus move v1 --target incus02 --target-project prod
Les périphériques de l’instance doivent correspondre sur le projet cible.
Les volumes de stockage personnalisés marqués comme dependent suivent l’instance lors de la migration.
Documentation : https://linuxcontainers.org/incus/docs/main/howto/move_instances/
Copie de fichiers à la première utilisation d’un volume personnalisé¶
Les périphériques disk utilisant un volume de stockage personnalisé et attachés à un conteneur disposent d’une nouvelle propriété initial.copy.
Lorsque celle-ci est définie à true, les données déjà présentes dans le chemin path à l’intérieur du conteneur sont copiées dans le volume à sa première utilisation, si ce dernier est vide. Cela correspond au comportement attendu pour les conteneurs d’application, dans lesquels des données initiales peuvent être présentes avant le montage de volumes par-dessus.
stgraber@vorash:~$ incus storage volume create default mysql-data
stgraber@vorash:~$ incus config device add mysql data disk pool=default source=mysql-data path=/var/lib/mysql initial.copy=true
La copie ne se produit qu’une fois par volume, et l’état est stocké dans la clef volatile.initial.copied du volume.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_disk/#initial-copy
Étiquettes de sécurité pour les instances¶
Une nouvelle clef de configuration d’instance security.tags permet de stocker une liste d’étiquettes séparées par des virgules.
Incus n’utilise pas ces étiquettes directement dans ses décisions d’autorisation, mais celles-ci sont exposées au backend d’autorisation. Avec OpenFGA, chaque étiquette devient un objet security_tag doté d’une relation tag avec toutes les instances sur lesquelles celle-ci est définie, permettant la gestion de politiques d’accès par catégories d’instances et plus par noms seuls.
stgraber@vorash:~$ incus config set c1 security.tags=pci,production
Documentation : https://linuxcontainers.org/incus/docs/main/authorization/#security-tags
Claims OIDC dans le scriptlet d’autorisation¶
L’argument details passé au scriptlet d’autorisation a désormais un champ Claims portant les claims validés du jeton OIDC du client.
Cela permet l’écriture de règles dépendant des claims du fournisseur d’identité, par exemple groups ou email, sans devoir en coder la logique dans le scriptlet.
Documentation : https://linuxcontainers.org/incus/docs/main/authorization/#scriptlet
Métriques pour les membres d’un cluster¶
L’endpoint /1.0/metrics renvoie désormais les informations des membres du cluster :
incus_cluster_member, avec l’architecture et le domaine de défaillance du membre ;incus_cluster_member_status, avec une ligne par état ;incus_cluster_member_role, avec une ligne par rôle ;incus_cluster_member_group, avec une ligne par groupe auquel le membre appartient.
Cela simplifie la mise en place d’alertes en cas d’indisponibilité ou d’évacuation de membres d’un cluster, directement depuis Prometheus.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/provided_metrics/
NVIDIA GPUDirect P2P pour les machines virtuelles¶
Les périphériques physiques gpu passés à une machine virtuelle ont désormais une clef de configuration nvidia.clique.
Définir le même numéro de clique (entre 0 et 15) sur plusieurs GPU passés à la même machine virtuelle les annonce au driver invité comme faisant partie d’une même clique GPUDirect P2P, permettant de faire du DMA entre les GPU.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_gpu/
Améliorations dans l’agent Windows¶
L’agent Windows permet désormais de lancer des sessions incus exec interactives, et gère mieux l’échange de signaux.
Machines virtuelles NetBSD¶
L’agent Incus est à présent disponible pour les invités NetBSD, ajoutant l’OS à la liste des OS Linux, FreeBSD, macOS et Windows déjà supportés.
Comme pour les autres systèmes BSD, définir image.os à une valeur débutant par NetBSD appliquera automatiquement un paramétrage adapté à la machine virtuelle.
Paquet FreeBSD pour le client en ligne de commande¶
Le client Incus est maintenant packagé dans FreeBSD Ports et peut être installé avec pkg install incus-client. Des binaires du client précompilés pour FreeBSD sont également fournis à chaque nouvelle version d’Incus.
Transfert de fichiers en mode archive¶
Les commandes incus file push et incus file pull ont désormais un drapeau --archive (ou -a), se comportant comme cp -a.
La propriété des fichiers, leur mode et leurs timestamps ne sont désormais préservés qu’avec cette option (qui active implicitement --recursive), les transferts réguliers se comportant à présent comme avec cp.
stgraber@vorash:~$ incus file pull --archive c1/etc/ ./etc-backup/
Étiquettes et environnement des images OCI¶
Les images importées depuis des registres OCI exposent à présent leurs étiquettes standards (org.opencontainers.image.*) comme des propriétés d’image oci.*, permettant de voir les informations telles que le titre, la version, la source ou encore la description de l’image dans incus image info, et de les afficher dans des colonnes dédiées avec incus image list.
L’environnement de l’image n’est désormais plus copié dans la configuration de l’instance au moment de sa création. Au lieu de cela, il est utilisé comme environnement par défaut dans incus exec, ne polluant pas la configuration de l’instance, et permettant à des mises à jour de l’image de changer cet environnement.
Paramétrage de l’usage de /etc/hosts dans le DNS des réseaux bridge¶
Les réseaux bridge ont désormais une clef de configuration dns.include_hosts, contrôlant si le dnsmasq dédié au réseau crée des enregistrements pour le fichier /etc/hosts de l’hôte.
Définir la propriété à false permet d’éviter d’exposer les enregistrements de l’hôte aux instances, préservant le confinement AppArmor.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/network_bridge/
Profilage des performances via l’API¶
Le profilage Go d’incusd via pprof est maintenant disponible sous /internal/debug/pprof/, restreint aux clients autorisés à administrer le serveur.
Contrairement à core.debug_address, l’endpoint d’API fonctionne en permanence en HTTPS sans changement de la configuration du serveur.
stgraber@vorash:~$ incus query --raw my-remote:/internal/debug/pprof/heap > heap.pprof
stgraber@vorash:~$ go tool pprof heap.pprof
Documentation : https://linuxcontainers.org/incus/docs/main/debugging/#profiling-incusd
Liste complète des changements¶
Voici une liste complète de tous les changements apportés par cette version :
Liste complète des commits
- incus-agent: Abstract exec process handling
- incus-agent: Report exit status of Windows exec sessions
- incus-agent: Fix PATHEXT for Windows exec sessions
- incus-agent: Forward exec signals on Windows
- incus-agent: Support interactive exec sessions on Windows
- incusd/instance/edk2: Add FirmwarePair.HasNVRAM
- incusd/scriptlet/qemu: Handle firmwares without NVRAM
- incusd/instance/qemu: Skip NVRAM handling with SeaBIOS firmware
- doc: Note NVRAM scriptlet functions need EDK2 firmware
- incusd: Validate OCI config.json before use
- incusd: Consistently say 'an NVRAM'
- incusd/instance/qemu: Close NVRAM file after writing
- incusd/instance/qemu: Never drop runtime state while QEMU is alive
- incusd/instance/qemu/qmp: Raise default command timeout to 2s
- client/oidc: Route provider requests through a dedicated transport
- client/oidc: Drop empty form parameters sent to the provider
- incusd/device: Allow importing dependent volumes with snapshots
- tests: Check dependent volume snapshots survive export/import
- incusd/storage/drivers: Add cluster size to qcow2 ImageInfo
- incusd/instance/qemu: Advertise qcow2 cluster size as discard granularity
- internal/io: Add GetUmask and Lchtimes helpers
- incus/file: Add --archive to file push/pull
- tests: Add --archive file transfer coverage
- i18n: Update translation templates
- incus/cluster: Don't use unix socket URL as the join address
- incus-agent: Externalize PTY logic
- incus-agent: Basic signal handling on Windows
- incus-agent: Add NetBSD agent
- incusd/instance/agent-loader: Add NetBSD files
- incusd/instance/agent-loader: Rename FreeBSD rc.d directory
- shared/osinfo: Add NetBSD
- incusd/instance/qemu: Add NetBSD support
- goreleaser: Add NetBSD
- doc/instance/create: Add NetBSD and update other agents
- github: Tune shellcheck exclusions
- doc/wordlist: Update wordlist
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Tamil)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Greek)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Portuguese)
- incusd/instance: Mention images available for other instance types
- incusd/images: Check source instance access on publish
- incusd/cluster: Wait for all blocking instance operations before evacuating
- incusd/instance: Apply evacuation guard to forwarded state changes
- incusd/instance/lxc: Check liblxc state when tolerating stop failures
- incusd/instance: Balance NUMA nodes on committed memory
- incusd/cluster: Stop Ready and Frozen instances before a restore migration
- incusd/instance: Reject stateless cluster moves of running instances
- incusd/device/tpm: Mount the instance volume when removing state
- incusd/instances: Prefer images.default_architecture for multi-arch sources
- incusd/instance/qmp: Split query and operational command timeouts
- incusd/instance/qmp: Tolerate monitor timeouts in blockJobWait
- incusd/instance/qemu: Report busy monitor as running
- incusd/instance/qemu: Log failure to resume after failed migration
- incusd/instance/qemu: Wait for the NBD server before blockdev-add
- incusd/instance/qemu: Accept qemu-kvm binary name in PID validation
- incus/image: Don't warn on already closed files during import
- Set PKCE challenge and verifier values
- cmd/generate-database/db: Add nullable field support
- incusd/network/bridge: Clean up tunnel interfaces on failed start
- incusd/network/physical: Restore the original MTU on stop
- incusd/instance: Treat pool and project changes as migrations
- api: network_bridge_dns_include_hosts
- incusd/network/bridge: Add dns.include_hosts
- doc: Update configs
- tests: Add dns.include_hosts test
- incusd/db/query: Fix giving-up warning in Retry
- incusd/cluster: Fix IsCowsqlNode return value
- incusd/cluster: Fix lock leak in heartbeat Send
- incusd/cluster: Fix typos
- doc: Mention FreeBSD client
- incusd: Restore in-memory config when update triggers fail
- incusd/config: Distinguish unset keys from explicit defaults
- tests: Add server config default value test
- incusd: Allow unsetting OVN connection when no OVN network exists
- tests: Add OVN server config test
- incusd/network/ovn: Inherit uplink bridge MTU when none is configured
- tests: Check OVN uplink veth MTU
- incusd: Don't close a nil pipe reader on backup failure
- incusd/storage/ceph: Fix qemu-nbd image spec
- tests: Add ceph librbd test
- github: Install qemu with librbd support for ceph tests
- cmd/incus: Remove url escape for spice socket path.
- incusd/storage/drivers: Add ReconnectQemuNbd and DisconnectQemuNbdWait
- incusd/storage/ceph: Reconnect NBD devices in place after resize
- tests: Add ceph-librbd driver to VM storage suites
- github: Run VM storage tests on ceph-librbd
- incus-agent: Fix paths on BSDs
- incus-agent: Factor code for UNIXes
- incus-agent: Please gofumpt
- incusd/instance/qemu/qmp: Be lenient about events with trailing \r
- incusd/instance/qemu: Disable multiport serial on NetBSD
- incusd/instance/drivers: Update serial tests
- doc/instance/create: Document new NetBSD tuning
- incusd/instance/config: Add volatile.last_state.agent.once
- incusd/instance/qemu: Make template application more robust
- doc: Update config
- incusd/instance/qemu: Remove unused argument
- incusd: Fix typo
- incusd/instance/agent-loader: Log agent output
- doc: Add multiport to wordlist
- incusd/rsync: Only transfer xattrs settable without CAP_SYS_ADMIN
- incusd/storage/zfs: Delete target volume before full transfer on refresh
- internal/linux: Add SparseFileWrapper
- incusd/storage: Use linux.SparseFileWrapper
- incusd/cluster/evacuation: Stop in place when scriptlet has no candidates
- incusd/mirror: Add file mirroring package
- internal/linux: Add SetMountReadOnly
- incusd/device/tpm: Run swtpm on a local mirrored copy of its state
- incusd/instance/qemu: Run QEMU on a local mirrored copy of the UEFI variables
- incusd/instance/qemu: Make the config volume read-only during live migration on shared storage
- incusd/storage: Flush local instance state before snapshots, copies and backups
- incusd/storage/drivers: Repair VM config volumes with recorded errors before mounting
- incusd/scriptlet: Track pending instance placements
- incusd/cluster/evacuation: Serialize target selection and record pending placements
- incusd/instance: Reserve NUMA nodes for starting and incoming instances
- incusd/apparmor/rsync: Allow reading destination ancestors
- incusd/api: Exclude node-local config from untargeted cluster ETag
- incusd/cluster: Reject internal rebalance/handover requests during startup
- incus/device: Set NVIDIA device UUIDs for physical GPUs
- incusd/storage/drivers: Add generic property cache
- incusd/storage/zfs: Use generic property cache
- incusd/storage/truenas: Use generic property cache
- incusd/storage/linstor: Add getVolumeIndex
- incusd/storage/linstor: Use filesystem stats for mounted volumes
- incusd/storage/linstor: Cache volume usage lookups
- incusd/storage/lvm: Cache thin volume usage lookups
- incusd/ovn: gofumpt
- incusd/instance/qmp: Handle ringbuf-read racing a chardev swap
- incusd/instance/qemu: Make ConsoleLog tolerant of concurrent console attach
- incusd/instance/lxc: Record migration transfer errors before signaling completion
- incusd/instance/qemu: Record migration transfer error before signaling completion
- incusd/project: Delete network peers on forced project deletion
- tests: Check forced project deletion with OVN peers
- incusd/images: Return error on invalid export request
- incusd/images: Preserve image type on push mode copy
- Translated using Weblate (Georgian)
- incusd/network/ovn: Limit initial connection setup
- incusd/network/ovn: Fail fast and name the database when unavailable
- incusd/network/acl: Resolve profile projects in a single transaction
- incusd/network/address-set: Resolve profile projects in a single transaction
- incusd/network/ovn: Scope mutual peer lookups to the target network
- incusd/instance/qemu: Don't pass nil exec streams to the agent client
- internal/server/storage/drivers: Handle dotted Ceph client IDs
- internal/server/util: Recognize named unconfined AppArmor profiles
- internal/server/instance/drivers: Unmount residual Unix devices during cleanup
- incusd/project: Fix unrestricted project check on volatile keys
- incusd/project: Allow snapshot restore with changed volatile keys
- tests: Add restricted project snapshot restore test
- tests: Cover OVN peering with several peers on one network
- incusd/instance/qmp: Make clearing the event handler sticky
- incusd/instance/qemu: Ignore duplicate stop hooks
- incusd/instance/lxc: Reuse exact-sized ID map gaps
- tests: Check exact-sized isolated ID map reuse
- api: gpu_physical_clique
- incusd/device/gpu: Add clique option to physical GPUs in VMs
- incusd/instance/qemu: Set x-nv-gpudirect-clique on passed-through GPUs
- doc: Document GPU clique option
- doc: Add DMA and GPUDirect to wordlist
- doc: Update configs
- incusd/instance: Fix project change dropped on cross-member moves
- tests: Add cross-project cluster move tests
- client: Don't attempt reconnection on websocket operations
- incusd/storage/zfs: Clean up parent dataset on failed migration
- shared/scriptlet: Flatten embedded pointer structs when marshalling
- api: authorization_scriptlet_claims
- incusd/request: Add OIDC claims context keys and forwarding header
- incusd/auth/oidc: Return validated claims from Auth
- incusd: Store validated OIDC claims in the request context
- incusd/cluster: Forward OIDC claims to other members
- incusd/auth: Expose OIDC claims to the authorization scriptlet
- doc: Document the Claims field of the authorization scriptlet
- incusd/mirror: Don't prune persistent files on start
- incusd/instance/qemu: Regenerate NVRAM when the symlink is dangling
- incus/server/network/driver/common: Remove loadbalancer bgp prefix on network delete
- incusd/instances: Log instance rendering failures
- incusd/backup: Fall back to the index config when backup.yaml is missing
- tests: Import a backup without backup.yaml
- incusd/firewall/nftables: Replace bridge filter chains atomically
- incusd/device/nic/bridged: Keep existing filters when an update fails
- incusd/network/acl: Reject rules the host firewall can't apply
- incusd/network/bridge: Validate ACL actions against the host firewall
- incusd/device/nic/bridged: Validate ACL actions against the host firewall
- doc: Note that allow-stateless is OVN only
- client: Fail clearly when OIDC provider has no device authorization endpoint
- incusd/instance/lxc: Hold the ID map lock until the allocation is persisted
- tests: Check concurrent isolated ID map allocation
- incusd/network/ovn: Match IPv6 load balancer health monitors
- incusd/instance: Add OCI config helpers
- incusd/instance/lxc: Export the OCI image environment as defaults
- incusd: Use the OCI image environment as exec defaults
- incusd: Stop copying the OCI environment into the instance config
- tests: Check OCI environment overrides and rebuild
- api: instance_project_move_live
- incusd/instance: Reject project moves when an attached volume can't follow
- incusd/instance: Reject project moves of instances with backups
- incusd/instance: Allow live project moves within a cluster
- incusd/instance: Resolve the volume project when removing dependent volumes
- incusd/storage: Fix migration type negotiation for dependent volumes
- incusd/instance: Pass the cluster move flag when negotiating dependent volume types
- incusd/instance: Let dependent volumes follow an instance across projects
- doc: Document live project moves
- tests: Add cross-project move tests
- incusd/instance/qemu: Reject live migration of filesystem dependent volumes
- incusd/storage: Resolve the volume project for dependent volumes
- incusd/instance: Resolve the volume project when deleting dependent volumes
- incusd/instance: Resolve the volume project for near-live dependent volume transfers
- incusd/instance: Let dependent volumes on local pools follow a project move to another member
- doc: Document dependent volumes in project moves with shared storage volumes
- tests: Add tests for dependent volumes in projects sharing storage volumes
- incusd: Keep the OS API reachable during shutdown
- incusd: Bound instance stops during shutdown
- incusd: Let a forced shutdown override one in progress
- incusd/storage/lvm: Use shared activation for ISO volumes on clustered pools
- incusd/storage/lvm: Rename both volumes of VM snapshots
- incusd/storage/lvm: Keep the original volumes until a restore fully succeeds
- tests: Rename VM snapshots before restoring them
- incusd/device: Reject unknown GPU types instead of passing through
- incusd/apparmor: Allow reading the local QEMU data directory
- tests: Check unknown GPU types are refused
- incusd/storage/zfs: Only reset datasets overriding the systemd ignore flag
- tests: Check delegated child datasets are reset
- incusd/firewall/nftables: Don't widen ACL rules for the other IP family
- tests: Check mixed-family ACL rule rendering
- incusd/firewall/nftables: Match ICMP on l4proto in ACL rules
- incusd/device/nic/bridged: Don't require br_netfilter for IPv6 filtering
- incusd/firewall/nftables: Allow DHCPv4 discovery through the forward chain
- tests: Check DHCPv4 exception and ICMPv6 ACL rendering
- incusd/firewall/nftables: Replace address set members in one transaction
- incusd/network/address-set: Reject overlapping addresses
- tests: Check a rejected address set edit keeps the applied set
- tests: Check bridged NIC ACL failures keep the filters
- incusd/instance: Don't shadow the project package name
- incusd/project: Re-check limits when recording instances and volumes
- incusd/storage: Check project limits when moving custom volumes
- incusd/cluster: Don't run update trigger under the gateway lock
- incusd/network/zone: Refresh TSIG cluster-wide and notify peers on creation
- incusd/network/bridge: Notify DNS peers on network update
- incus/remote: Make remote name checks stricter
- shared/cliconfig: Include diagnosis data in error path
- incus/usage: Defer remote error handling and clarify messages
- incus/list: Clarify --all-remotes usage
- incus: Hint missing space after remote on empty match list
- i18n: Update translation templates
- api: metrics_cluster_members
- incusd/metrics: Add cluster member metric types
- incusd/metrics: Add cluster member info, status and role metrics
- tests: Check cluster member metrics
- doc: Document cluster member metrics
- Added incant to the list of third party software
- Translated using Weblate (Portuguese)
- incusd/cluster: Include member lookups in heartbeat round duration
- incusd/cluster: Stamp member heartbeats at write time
- incusd/db: Add GetNICConflictCandidateIDs
- incusd/device/nic_bridged: Only load instances that may conflict
- incusd: Only query local instances for forwarded instance listings
- incusd/instances: Load local instances in one query when listing all projects
- incusd/storage: Fix custom volume usage always reporting zero total size
- api: instance_security_tags
- incusd/auth: Add security tag object type
- incusd/auth: Add instance security tags to the authorizer interface
- incusd/auth: Add security tags to the OpenFGA model
- incusd/auth: Add security tag support to OpenFGA
- incusd/auth: Update generated OpenFGA model
- shared/validate: Add IsSecurityTagList
- incusd/instance: Add security.tags
- incusd/instance: Sync security tags with the authorizer
- incusd: Include security tags in OpenFGA resource sync
- incusd/patches: Add auth_openfga_security_tags
- doc: Update configs
- tests: Add OpenFGA security tags test
- doc: Document security tags
- internal/filter: Add RegexpToLike
- incusd/instances: Push simple name filters down to the database
- incusd/instances: Forward filters to other cluster members
- incusd/instance/qemu: Abort snapshot transfer on failed live migration
- incusd/instance: Reject security.idmap.base on isolated containers
- incusd/instance/lxc: Use fixed ID map bases on non-isolated containers
- incusd/patches: Disable isolation on containers with a fixed ID map base
- incusd/instance: Update security.idmap.base description
- doc: Update configs
- doc: Describe fixed ID map ranges
- tests: Cover fixed ID map ranges
- incusd/db: Turn nodeSpecificNetworkConfig into network type aware function
- incusd: Switch usages to network type aware IsNodeSpecificNetworkConfig
- incusd/network/ovn: Add DeleteLogicalRouterNATByLogicalIP
- incusd/network/ovn: Resolve the network owning the logical router
- incusd/network/ovn: Support networks sharing a logical router
- incusd/network/ovn: Add support for child networks
- incusd/network: Put OVN networks with a parent in the logical dependency group
- incusd/network/ovn: Handle child networks in router wide features
- api: network_ovn_parent
- doc: Document OVN child networks
- doc: Update configs
- tests: Add OVN child network tests
- incusd/seccomp: Retry pidfd_open with PIDFD_THREAD on ENOENT
- incusd/network/ovn: Don't load a self-referencing parent
- incus/server/storage/driver/ceph: Flatten image in background during instance creation
- incusd/storage/ceph: Only flatten clones and wait for it before deleting
- incusd/storage/ceph: Release the source snapshot after flattening
- incusd/storage/ceph: Describe background flattening for ceph.rbd.clone_copy
- doc: Update configs
- tests: Cover ceph.rbd.clone_copy=false copies
- api: Add disk_initial_copy extension
- incusd/storage: Add volatile.initial.copied volume key
- incusd/device/disk: Add initial.copy for custom volumes
- incusd/instance/lxc: Allow adding initial.copy disks to existing instances
- tests: Add initial.copy disk test
- doc: Document initial.copy
- doc: Update configs
- client/oci: Expose OCI image labels as oci.* image properties
- tests: Cover OCI image labels
- incusd/profiles: Check project restrictions on profile creation
- incusd/network/ovn: Route child networks through the parent's peerings
- incusd/network/acl: Match the child networks of a peer
- incusd/network/ovn: Allow NAT addresses on child networks
- tests: Cover peering and NAT addresses with OVN child networks
- doc: Document peering and NAT addresses on OVN child networks
- api: Add internal_debug_pprof extension
- incusd: Add /internal/debug/pprof
- tests: Cover /internal/debug/pprof over HTTPS
- doc: Document profiling through the API
- incusd/cluster: Disconnect source client after restore
- incusd/instance/qemu: Only watch console disconnection for text console
- incusd/console: Time out waiting for websockets to connect
- incusd/logging: Don't block event delivery when Loki can't keep up
- incusd/instance: Cache boot time when computing process start time
- shared/resources: Read interface counters from sysfs
- incusd/instance/qemu: Read NIC counters directly for metrics
- incusd/metrics: Reduce allocations when rendering metrics
- shared/resources: Parse the PCI ID database only once
- shared/resources: Avoid over-allocating when reading sysfs files
- shared/resources: Resolve udev links once and count processes cheaply
- Update gomod
- doc/rest-api: Refresh swagger YAML
- incus/file: Contain recursive pull symlinks
- incusd: Don't follow symlinks when receiving migration data
- incusd/storage: Treat volume creation with a source as a copy
- incusd/storage/drivers: Confine btrfs subvolume paths
- incusd/storage: Validate dependent volume names on backup import
- incusd/storage: Ignore backup project for dependent volumes
- incusd/storage/s3: Require x-amz-* headers to be signed
- incusd/operations: Check project access on operation get and wait
- incusd/operations: Hide access token operations from non-admins
- incusd/storage/buckets: Require can_edit to read bucket keys
- incusd/project: Restrict volume options on update and copy
- incusd/instances: Check project restrictions on clustered refresh
- Release Incus 7.5
Documentation¶
La documentation d’Incus peut être consultée sur :
https://linuxcontainers.org/incus/docs/main/
Paquets¶
Incus ne fournit pas de paquet d’installation mais bien un tarball à chaque version. Vous trouverez ci-dessous différentes solutions pour mettre Incus en service.
Installation du serveur Incus sous Linux¶
Incus est disponible sur la plupart des distributions Linux courantes. Vous trouverez des instructions d’installation détaillées dans notre documentation.
https://linuxcontainers.org/incus/docs/main/installing/
Paquet Homebrew du client Incus¶
Le client Incus est disponible sur Homebrew pour Linux et macOS.
https://formulae.brew.sh/formula/incus
Paquet Chocolatey du client Incus¶
Le client Incus est disponible sur Chocolatey pour les utilisateurs de Windows.
https://community.chocolatey.org/packages/incus/7.5.1
Paquet Winget du client Incus¶
Le client Incus est aussi disponible sur Winget pour les utilisateurs de Windows.
https://winstall.app/apps/LinuxContainers.Incus
Support¶
Les versions de fonctionnalité d’Incus ne sont supportées que jusqu’à la sortie de la suivante. Les personnes souhaitant un support plus long et des changements moins fréquents devraient plutôt envisager d’utiliser Incus 7.0 LTS.
Le support communautaire est disponible sur : https://discuss.linuxcontainers.org
Un support commercial est disponible sur : https://zabbly.com/incus
Les bugs peuvent être signalés sur : https://github.com/lxc/incus/issues
Incus 7.4 est maintenant disponible¶
28 août 2026
L’équipe d’Incus est heureuse d’annoncer la sortie d’Incus 7.4 !
Ce fut encore un mois bien rempli pour nous, avec au programme un grand ménage dans les problèmes nous ayant été remontés sur Github, des résolutions de bugs assez anciens et un bon nombre de nouvelles fonctionnalités !
Comme d’habitude, vous pouvez l’essayer vous-même en ligne : https://linuxcontainers.org/incus/try-it/
Correctifs de sécurité¶
Cette version corrige 2 vulnérabilités :
- CVE-2026-81500 (modérée) – Client-side path traversal when exporting an image from a malicious server
- CVE-2026-81501 (modérée) – Private image import from another project by a restricted client
Nouvelles fonctionnalités¶
Gestion des clefs UEFI Secure Boot¶
Suite à l’ajout de la fonctionnalité d’interaction avec la NVRAM dans Incus 7.3, cette nouvelle version ajoute tout un outillage autour des bases de clefs UEFI Secure Boot pour les machines virtuelles.
Une nouvelle commande incus low-level secureboot permet de lister, ajouter, supprimer, exporter et importer des entrées de bases de clefs Secure Boot.
stgraber@vorash:~$ incus low-level secureboot list v1 db
┌──────┬───────────────────────┬──────────────┬───────────────────────────────────────┐
│ TYPE │ OWNER GUID NAME │ FINGERPRINT │ SUBJECT │
├──────┼───────────────────────┼──────────────┼───────────────────────────────────────┤
│ x509 │ MICROSOFT_VENDOR_GUID │ 48e99b991f57 │ Microsoft Corporation UEFI CA 2011 │
│ │ ├──────────────┼───────────────────────────────────────┤
│ │ │ 076f1fea90ac │ Windows UEFI CA 2023 │
│ │ ├──────────────┼───────────────────────────────────────┤
│ │ │ e5be3e64c6e6 │ Microsoft Option ROM UEFI CA 2023 │
│ │ ├──────────────┼───────────────────────────────────────┤
│ │ │ e8e95f0733a5 │ Microsoft Windows Production PCA 2011 │
│ │ ├──────────────┼───────────────────────────────────────┤
│ │ │ f6124e34125b │ Microsoft UEFI CA 2023 │
└──────┴───────────────────────┴──────────────┴───────────────────────────────────────┘
Les personnes souhaitant un contrôle total de l’état de base de la NVRAM peuvent à présent utiliser le nouvel ensemble de clefs de configuration d’instance initial.*, idéal pour des profils.
initial.secureboot.pk,initial.secureboot.kek,initial.secureboot.db,initial.secureboot.dbx,initial.secureboot.dbtetinitial.secureboot.mok, pour enrôler des clefs dans l’une des bases de clefs Secure Boot ;initial.nvram.<GUID>.<nom>etinitial.nvram-binary.<GUID>.<nom>, pour définir des variables dans la NVRAM.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/instance_options/
Migration quasi à chaud de conteneurs¶
La migration à chaud de conteneurs via CRIU a toujours été assez fragile, puisqu’elle impose aux processus de n’utiliser que des fonctionnalités compatibles avec CRIU.
Incus 7.4 ajoute une alternative pour les conteneurs tournant sur du stockage local, la migration quasi à chaud.
Plutôt que de transférer l’état de la mémoire, seul le système de fichiers est transféré au serveur cible, par l’intermédiaire d’une série d’instantanés incrémentaux à chaud. Seul le dernier instantané demande l’arrêt du conteneur, après quoi il est démarré à nouveau sur le serveur cible.
Il ne s’agit pas d’une migration à chaud puisque le conteneur est redémarré, mais le temps d’arrêt est limité au dernier transfert d’instantané, lequel est habituellement très rapide, permettant à des gros conteneurs d’être déplacés avec très peu d’indisponibilité.
La fonctionnalité peut être utilisée avec le nouveau drapeau --refresh de incus move, à la fois pour des déplacements au sein d’un cluster ou vers des serveurs distants :
stgraber@vorash:~$ incus move c1 --target incus02 --stateless --refresh
ou
stgraber@vorash:~$ incus move c1 remote-server:c1 --stateless --refresh
Une valeur refresh-migrate correspondante est maintenant disponible pour la clef de configuration d’instance cluster.evacuate, permettant d’utiliser ce comportement lors des évacuations.
Notez que la fonctionnalité ne concerne que les conteneurs et n’est disponible que pour ZFS et btrfs, les autres drivers de stockage ne disposant pas de mécanisme de transfert d’instantanés efficace entre serveurs.
Documentation : https://linuxcontainers.org/incus/docs/main/howto/move_instances/
Modification temporaire de la séquence de démarrage des VM¶
La commande incus start a désormais un nouveau drapeau --override-boot permettant de choisir, pour une VM, la prochaine entrée de démarrage utilisée.
Il est possible de passer soit le numéro de la prochaine entrée de démarrage, soit aucun paramètre, auquel cas une liste interactive des options disponibles est présentée.
stgraber@vorash:~$ incus start v1 --override-boot
┌────┬────────────────────────────────┬────────────────────────────────────────────────────────────────────────────────────────┐
│ ID │ DESCRIPTION │ PATH │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 0 │ BootManagerMenuApp │ Fv(64074afe-340a-4be6-94ba-91b5b4d0f71e)/FvFile(eec25bdc-67f2-4d95-b1d5-f81b2039d11d) │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 1 │ EFI Firmware Setup │ Fv(64074afe-340a-4be6-94ba-91b5b4d0f71e)/FvFile(462caa21-7614-4503-836e-8ab6f4662331) │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 2 │ UEFI QEMU QEMU HARDDISK │ PciRoot(0x0)/Pci(0x1,0x1)/Pci(0x0,0x0)/Scsi(0x0,0x1) │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 3 │ UEFI PXEv4 (MAC:10666AA0CED7) │ PciRoot(0x0)/Pci(0x1,0x4)/Pci(0x0,0x0)/MAC(10666aa0ced7,0x1)/IPv4(0.0.0.0,0x0) │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 4 │ UEFI PXEv6 (MAC:10666AA0CED7) │ PciRoot(0x0)/Pci(0x1,0x4)/Pci(0x0,0x0)/MAC(10666aa0ced7,0x1)/IPv6(::,0x0,Static) │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 5 │ UEFI HTTPv4 (MAC:10666AA0CED7) │ PciRoot(0x0)/Pci(0x1,0x4)/Pci(0x0,0x0)/MAC(10666aa0ced7,0x1)/IPv4(0.0.0.0,0x0)/Uri() │
├────┼────────────────────────────────┼────────────────────────────────────────────────────────────────────────────────────────┤
│ 6 │ UEFI HTTPv6 (MAC:10666AA0CED7) │ PciRoot(0x0)/Pci(0x1,0x4)/Pci(0x0,0x0)/MAC(10666aa0ced7,0x1)/IPv6(::,0x0,Static)/Uri() │
└────┴────────────────────────────────┴────────────────────────────────────────────────────────────────────────────────────────┘
Select next boot entry: 1
Partage de réseaux avec des projets restreints¶
Les projets dans lesquels features.networks est activé peuvent désormais se voir accorder l’accès à une liste de réseaux du projet default, via la clef de configuration restricted.networks.access.
Les réseaux ainsi listés sont partagés avec le projet, apparaissent dans incus network list, et sont utilisables par les instances du projet. Il est bien sûr toujours possible pour le projet de gérer ses propres réseaux dédiés via OVN. La fonctionnalité permet de fournir un bridge ou un uplink commun à un projet restreint, sans sacrifier la possibilité pour celui-ci de gérer ses propres réseaux.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/projects/
Support de DNS NOTIFY pour les zones réseau¶
Le serveur DNS interne utilisé pour gérer les zones réseau envoie désormais des messages DNS NOTIFY à tous les pairs configurés dès que le contenu d’une zone change.
Cela permet aux serveurs DNS secondaires de rafraîchir les zones sans avoir à attendre le délai de rafraîchissement de celles-ci. De ce fait, ce délai a été augmenté à 15 minutes.
Documentation : https://linuxcontainers.org/incus/docs/main/howto/network_zones/
Nouveau rendu des tableaux dans la CLI¶
Nous avons modifié l’affichage des listes dans la CLI, offrant un rendu plus propre et légèrement plus compact.
stgraber@vorash:~$ incus list
┌─────────────┬─────────┬─────────────────────────┬──────────────────────────────────────────────────┬─────────────────┬───────────┐
│ NAME │ STATE │ IPV4 │ IPV6 │ TYPE │ SNAPSHOTS │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ caddy-test │ STOPPED │ │ │ CONTAINER (APP) │ 0 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ dev-os │ STOPPED │ │ │ VIRTUAL-MACHINE │ 1 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ isolated-oc │ STOPPED │ │ │ VIRTUAL-MACHINE │ 0 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ rhel10 │ RUNNING │ 10.10.10.225 (eth0) │ 2602:fc62:ef:1010:1266:6aff:fe69:dd25 (eth0) │ CONTAINER (APP) │ 0 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ rl9 │ RUNNING │ 10.10.10.60 (enp5s0) │ 2602:fc62:ef:1010:fac2:13b0:9ad7:918e (enp5s0) │ VIRTUAL-MACHINE │ 0 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ test │ RUNNING │ 10.226.131.1 (incusbr0) │ fd42:10b9:5a70:b459::1 (incusbr0) │ VIRTUAL-MACHINE │ 0 │
│ │ │ 10.10.10.73 (_venp5s0) │ 2602:fc62:ef:1010:1266:6aff:fe11:9cfd (_venp5s0) │ │ │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ u24 │ RUNNING │ 10.10.10.66 (enp5s0) │ 2602:fc62:ef:1010:1266:6aff:fe22:9e8 (enp5s0) │ VIRTUAL-MACHINE │ 0 │
├─────────────┼─────────┼─────────────────────────┼──────────────────────────────────────────────────┼─────────────────┼───────────┤
│ v1 │ RUNNING │ 10.76.140.1 (incusbr0) │ fd42:75ef:6c01:accd::1 (incusbr0) │ VIRTUAL-MACHINE │ 0 │
│ │ │ 10.10.10.69 (enp5s0) │ 2602:fc62:ef:1010:1266:6aff:fe17:7e7f (enp5s0) │ │ │
└─────────────┴─────────┴─────────────────────────┴──────────────────────────────────────────────────┴─────────────────┴───────────┘
Backend librbd pour Ceph RBD¶
Le driver de stockage ceph a désormais une clef de configuration ceph.rbd.backend.
Lorsque celle-ci est définie à librbd, l’accès aux volumes se fait par l’intermédiaire de librbd et non du driver RBD du noyau (krbd).
Cela permet d’utiliser les fonctionnalités de RBD qui ne sont pas supportées par le driver du noyau, et peut aider dans les environnements dans lesquels celui-ci présente des problèmes de stabilité.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/storage_ceph/
Récupération de pools de stockage partagés dans un cluster¶
incus admin recover peut à présent récupérer des pools de stockage partagés sur les serveurs en cluster, permettant de restaurer les données des clusters ayant perdu leur base de données.
La procédure considère que la même configuration est utilisée sur chaque serveur du cluster, et que celui qui traite la requête de récupération prendra le contrôle de tout ce qui est récupérable.
Documentation : https://linuxcontainers.org/incus/docs/main/howto/disaster_recovery/
Certificats client propres aux serveurs distants¶
incus remote add a désormais des drapeaux --tls-cert, --tls-key et --tls-p12, permettant de charger un certificat client propre au serveur distant créé.
La fonctionnalité permet notamment de travailler dans des environnements dans lesquels l’accès aux serveurs est géré par des certificats générés transmis aux utilisateurs, et non des jetons de confiance.
De tels environnements peuvent par example se retrouver dans des entreprises gérant leur propre CA interne.
Un autre exemple d’utilisation est la possibilité de télécharger IncusOS pré-provisionné avec un certificat client créé automatiquement.
stgraber@vorash:~$ incus remote add incus-os https://10.10.10.100 --tls-p12 ~/Downloads/client.pfx
Password for /home/stgraber/Downloads/client.pfx:
Support des en-têtes et des données binaires pour les requêtes brutes vers l’API¶
incus query permet désormais d’utiliser des en-têtes HTTP personnalisés avec le drapeau -H.
Il est également possible à présent de transmettre des données binaires avec incus query par l’intermédiaire de l’option --data-file.
Cela permet d’utiliser la commande avec des endpoints d’API s’attendant à recevoir des en-têtes particuliers ou des données binaires, comme c’est le cas pour l’API des fichiers.
stgraber@vorash:~$ incus query -X POST --data-file ./f.txt -H "X-Incus-type: file" -H "X-Incus-mode: 0600" /1.0/instances/c1/files?path=/root/f.txt
Accès à la NVRAM depuis le scriptlet QEMU¶
Le scriptlet QEMU peut désormais inspecter et modifier la NVRAM au travers des nouvelles fonctions suivantes :
get_nvram_varhas_nvram_varset_nvram_varunset_nvram_varget_raw_nvram_varset_raw_nvram_varlist_nvram_vars
Documentation : https://linuxcontainers.org/incus/docs/main/reference/instance_options/#qemu-scriptlet
Configuration du multicast sur OVN¶
Les réseaux OVN ont désormais deux nouvelles clefs de configuration, bridge.multicast_snooping et bridge.multicast_relay.
La première contrôle le snooping IGMP/MLD sur le switch virtuel, ne transmettant le trafic multicast qu’aux ports ayant souscrit au groupe, et la seconde permet de relayer le trafic multicast via le routeur logique du réseau.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/network_ovn/
Contrôle des annonces de routeur IPv6¶
Une nouvelle clef de configuration ipv6.ra est maintenant disponible pour les réseaux bridge et ovn, contrôlant si les annonces de routeur IPv6 sont envoyées sur le réseau.
Limites d’E/S en pointe pour les disques¶
Les périphériques disk attachés à des VM disposent des nouvelles clefs de configuration limits.read.burst, limits.write.burst et limits.max.burst, avec la même syntaxe que les limites classiques (octets et/ou opérations par seconde), permettant de définir les limites autorisées en pointe.
Les clefs correspondantes limits.read.burst.length, limits.write.burst.length et limits.max.burst.length définissent la durée des pointes (par défaut une seconde).
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_disk/
Limites d’E/S en pointe pour les cartes réseau¶
Les périphériques nic disposent des nouvelles clefs de configuration limits.ingress.bucket, limits.egress.bucket et limits.max.bucket permettant de définir la quantité de données (en bits) pouvant être utilisée au-delà de la limite autorisée. Les cartes réseau bridged, p2p et routed disposent également à présent des clefs limits.ingress.burst, limits.egress.burst et limits.max.burst contrôlant le débit maximal des pointes.
Les cartes ovn ne disposent que des clefs en .bucket.
Politiques de mise en file pour les cartes réseau¶
Les cartes réseau bridged, p2p et routed ont une nouvelle clef de configuration queue.discipline contrôlant la politique de mise en file utilisée côté hôte.
Pour les machines virtuelles, le côté hôte d’une interface est un périphérique TAP avec plusieurs files, et queue.discipline.attach contrôle si la politique est attachée à chaque file (queue) ou à l’interface entière (root).
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_nic/
Colonnes pour les propriétés des images¶
incus image list supporte à présent des colonnes personnalisées properties:CLEF, ajoutant une colonne pour chaque propriété demandée.
stgraber@vorash:~$ incus image list images: debian/13 --columns lfpd,properties:os,properties:release,properties:variant
┌──────────────────────────────────┬──────────────┬────────┬────────────────────────────────────────────────┬────────┬─────────┬─────────┐
│ ALIAS │ FINGERPRINT │ PUBLIC │ DESCRIPTION │ OS │ RELEASE │ VARIANT │
├──────────────────────────────────┼──────────────┼────────┼────────────────────────────────────────────────┼────────┼─────────┼─────────┤
│ debian/13 (7 more) │ 065c3e644af0 │ yes │ Debian trixie amd64 (20260827_05:24) │ Debian │ trixie │ default │
│ ├──────────────┼────────┼────────────────────────────────────────────────┼────────┼─────────┼─────────┤
│ │ b8a6f9f60d67 │ yes │ Debian trixie amd64 (20260827_05:24) │ Debian │ trixie │ default │
├──────────────────────────────────┼──────────────┼────────┼────────────────────────────────────────────────┼────────┼─────────┼─────────┤
│ debian/13/arm64 (3 more) │ 4189835984b2 │ yes │ Debian trixie arm64 (20260827_05:24) │ Debian │ trixie │ default │
│ ├──────────────┼────────┼────────────────────────────────────────────────┼────────┼─────────┼─────────┤
│ │ e08e7964a29a │ yes │ Debian trixie arm64 (20260827_05:24) │ Debian │ trixie │ default │
└──────────────────────────────────┴──────────────┴────────┴────────────────────────────────────────────────┴────────┴─────────┴─────────┘
Localisation des images dans un cluster¶
Les images d’un cluster indiquent désormais dans un champ locations la liste des serveurs du cluster qui en possèdent une copie.
Interdiction de démarrer des instances¶
Une nouvelle clef de configuration d’instance security.protection.start a été ajoutée. Lorsqu’elle est définie à true, elle empêche le démarrage de l’instance.
La fonctionnalité est particulièrement intéressante pour définir des modèles d’instances ou gérer des environnements décommissionnés ou dédiés au seul stockage de sauvegardes.
stgraber@vorash:~$ incus config set c1 security.protection.start=true
stgraber@vorash:~$ incus start c1
Error: Instance is protected against being started
Certificat d’endpoint Ceph Object¶
La clef de configuration cephobject.radosgw.endpoint_cert_file pour les pools de stockage cephobject a été remplacée par cephobject.radosgw.endpoint_cert.
Incus tente de limiter autant que possible les références à des fichiers locaux dans sa configuration, au vu de la difficulté de gérer ceux-ci dans des environnements en cluster.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/storage_cephobject/
Mise à jour des dépendances minimales¶
Avec la sortie de Go 1.27, Incus demande à présent au moins Go 1.26.
De plus, les améliorations récentes dans notre support d’OVN demandent maintenant au moins OVS 3.3.0 et OVN 24.03.0.
Liste complète des changements¶
Voici une liste complète de tous les changements apportés par cette version :
Liste complète des commits
- incus/low-level: Fix naming inconsistency
- i18n: Update translation templates
- shared/api: Hide additional sensitive config keys
- incusd/instance/qmp: Bump query-migrate timeout
- incusd/db: Have NetworkNodeConfigs only consider the requested network
- incusd/network/ovn: Skip empty transactions in SetChassisGroupPriority
- generate-database: Fix GetMany generation for entities without filters
- docs: Clarify the sentence about Incus owning the ZFS pool/dataset
- incusd/daemon: Drop else branches in project expansion
- incusd/bgp: Resolve neighbor address for unnumbered peers
- incus/remote: Restrict proxy /1.0 cache to GET and invalidate on changes
- incusd/endpoints: Fix proxy protocol handling
- incusd/storage: Unmount leftover mounts in CleanupInstancePaths
- incusd/device: Check interface isn't in use by host before passthrough
- incusd/instance/lxc: Fix mount options of OCI /run tmpfs
- incusd/instance/lxc: Skip OCI /run tmpfs when image populates /run
- incusd/cluster: Stop instances in place when evacuation has no target
- api: instance_protection_start
- internal/instance: Add security.protection.start
- incusd/instance: Add support for security.protection.start
- doc: Update config
- incusd/instance: Clarify protection errors
- incusd/forknet: Fix concurrent DHCP resolv.conf handling
- incusd/instance: Update oci.dns.* descriptions
- doc: Update config
- incusd/instance/lxc: Enable edns0 in OCI resolv.conf
- incusd/forknet: Enable edns0 in resolv.conf
- incus: Add support for client-side near-live migration
- incus: Add refresh flag to move
- incusd/instance/drivers: Prevent migration of dependent disk during final sync
- i18n: Update translation templates
- shared/uefi: Various device path fixes
- api: instance_nvram_bulk_update
- client: Add NVRAM bulk update
- incusd/instances: Add NVRAM bulk update
- doc/rest-api: Refresh swagger YAML
- incus/low-level: Accept multiple arguments for nvram set and unset
- client: use a copy of ProtocolIncus for WithContext
- incus/low-level: Allow unsetting nvram with empty set value
- i18n: Update translation templates
- client: Preserve tempPath in UseProject and UseTarget
- incusd/network/ovn: Replace stale SNAT rule on external address change
- incusd/device/nic_ovn: Allow live update of ipv4/ipv6.address.external
- incusd/db: Add generated network, network_config and network_node entities
- incusd/db: Add GetCreatedNetworksInfo
- incusd/network: Add LoadAllCreated
- incusd/network: Reduce database queries in OVN network startup
- incusd/networks: Reduce database queries during network startup
- incusd: Use cached server name for warning operations
- incusd/cluster: Add ConnectIfBucketIsRemote
- incusd: Add forwardedResponseIfBucketIsRemote
- incusd: Forward storage bucket requests to the cluster member holding the bucket
- doc: Document storage bucket handling in clusters
- internal/migration: Don't double close websocket writer
- incusd/instance/qmp: Ignore timeouts during migration
- incusd/network/ovn: Don't replace DNAT rules sharing a logical IP
- incusd/network/ovn: Use tag_request on nested switch ports
- tests: Add OVN test suite
- tests: Register OVN tests
- github: Add OVN tests job
- doc/requirements: Bump minimum OVS/OVN versions
- Makefile: Bump minimum OVS/OVN versions
- internal/server/network: Update generated OVSDB schemas
- incusd/network/ovn: Add logical switch port ARP proxy helpers
- incusd/network/ovn: Use ARP proxy for l2proxy uplink ingress
- incusd/network/ovn: Add GetLogicalRouterNATs
- incusd/patches: Convert OVN l2proxy NAT rules to ARP proxy
- tests: Convert OVN l2proxy NAT checks to ARP proxy
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Tamil)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Greek)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- client: Handle unmanaged networks in preseed
- incusd/storage/lvm: Wipe source device rather than VG name
- incusd: Add instanceShutdownOrForceStop
- incusd: Allow cluster-internal instance changes on evacuated members
- shared/api: Add 'Refresh' to InstancePost
- incus/move: Pass Refresh to InstancePost
- incusd: Add support for near-live migration
- incusd: Add support for 'refresh-migrate' action in evacuation path
- internal/instance: Add 'refresh-migrate' option to 'cluster.evacuate'
- tests: Add tests for near-live migration
- doc: Update config
- api: instance_refresh_migration
- doc/rest-api: Refresh swagger YAML
- i18n: Update translation templates
- client: Detect dead event connections
- incusd/events: Deliver events in order
- incusd/projects: Send project-updated after the update
- client: Add EventListener.SetOrdered
- doc: Document event ordering
- client: Fix Disconnect not disconnecting
- incusd/storage/lvm: Detect block type in ListVolumes
- incusd/storage: Tolerate missing snapshot record on delete
- incusd/storage: Repair snapshot records on refresh
- incus/admin_sql: Fix integer rendering
- api: image_locations
- shared/api: Add Locations to Image
- incusd/db/images: Fill in image locations
- doc/rest-api: Refresh swagger YAML
- api: network_ovn_multicast
- incusd/network/ovn: Add multicast helpers
- incusd/network/ovn: Add bridge.multicast_snooping and bridge.multicast_relay
- doc: Update configs
- incusd/instance/qemu: Use temporary data-file when growing metadata image
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Tamil)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Greek)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- tests: Skip OVN tests when INCUS_OFFLINE is set
- tests: Add cgroup test suite
- github: Add cgroup tests job
- tests: Add interception test suite
- github: Add interception tests job
- tests: Add network bridge firewall test suite
- github: Add network bridge firewall tests job
- tests: Add storage buckets drivers test suite
- github: Add storage buckets drivers tests job
- Translated using Weblate (Portuguese)
- doc: Document instance-migrated lifecycle event
- incusd/storage/linstor: Fix snapshot resource definition races
- incusd/storage/cephfs: Sync filesystem before snapshot creation
- tests: Wait for nc listeners in network address set test
- tests: Use a 4GiB btrfs test pool
- incusd: Retry transient database errors in the admin SQL endpoint
- incusd/db: Make AddImageToLocalNode idempotent
- tests: Wait for monitor subscription in dev-incus test
- incusd: Retry cluster role handover while another change is in progress
- instance: Derive process start time from proc stat
- incusd/storage/linstor: Mount snapshot volumes read-only
- incus/create: Allow --environment-file to be passed multiple times
- incus: Mention repeatable flags in help strings
- i18n: Update translation templates
- shared/simplestreams: Include variant in image description
- client: Fix crash on listener disconnect without error
- incusd/network/zone: Allow underscore-prefixed names
- incusd/patches: Upgrade OpenFGA model
- incusd: Use x-example in swagger operation parameters
- incusd: Fix header definitions in swagger comments
- incusd: Fix body parameters in swagger comments
- incusd/instance_nvram: Mark var path parameter as required
- incusd: Fix response examples in swagger comments
- shared/api: Drop invalid examples from preseed structs
- shared/api: Drop swagger:model from metadata map key types
- incusd/metadata: Fix swagger definition of configuration endpoint
- incusd/storage: Fix swagger body definition for volume backup rename
- test/lint: Validate swagger spec
- doc/rest-api: Refresh swagger YAML
- incusd: Fix storage volume project expansion
- tests: Cover inherited storage volume authorization
- incusd/storage/linstor: Retry resource definition deletion
- tests: Use future expiry for volume snapshot property test
- incusd: Make cluster role handover resilient to leader changes
- shared/tls: Renew certificates at 80% of validity period
- incusd/acme: Update for CertificateNeedsUpdate change
- incusd/acme: Run renewal check hourly
- incusd: Give up on cluster database after failed role handover
- incusd/images: Propagate old image deletion errors during refresh
- incusd/storage/btrfs: Wait for quota rescan after enabling quotas
- incusd: Bound global database close during shutdown
- incusd/instance/qemu: Record maxcpus in boot state
- incusd/db/cluster: Make node_cluster_group deletion a DeleteMany
- incusd: Fix PATCH of cluster group with multiple members
- global: Fix warnings on double file close
- incusd: Simplify global database shutdown
- incusd/events: Send events outside of the lock
- gomod: Update go-cowsql
- incusd/storage/linstor: Enforce minimum DRBD volume size
- incusd/storage/linstor: Enforce exact DRBD volume sizes
- incusd/storage/lvm: Only grow snapshot CoW capacity when needed
- incusd/qemu: Make generated configuration deterministic
- github: Drop storage_buckets_drivers from extended tests
- tests: Switch to debian/13 test image
- github: Run network_bridge_firewall test on arm64
- tests: Allow overriding the CLI command timeout
- tests: Add cpu vm test suite
- tests: Add guestapi vm test suite
- tests: Add network routed test suite
- tests: Add storage disks vm test suite
- tests: Add storage vm test suite
- tests: Add storage volumes vm test suite
- github: Add VM tests job
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Tamil)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Greek)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- shared/uefi: Diverse fixes
- shared/uefi: Refactor dissection primitives
- shared/uefi: Add missing writers
- shared/uefi: Add formatting primitives
- shared/uefi: Add device path string representation lexer
- shared/uefi: Add device path formatting
- shared/uefi: Add device path tests
- shared/uefi: Implement Boot#### formatting
- incus/image: Add support for properties columns in image list
- i18n: Update translation templates
- doc/storage: Add TrueNAS to data storage location table
- lxc: Start live migration action operation before pre-dumps
- incusd/network/ovn: Handle dynamic addresses and removal for ipv4/ipv6.address.external
- incusd/device/nic_ovn: Remove stale SNAT rules on external address update
- incusd/firewall: Restrict wildcard proxy NAT to local addresses
- tests: Update proxy NAT wildcard listen address checks
- incusd/images: Split pruneExpiredImage into its own function
- incusd/images: Hold image lock when pruning and auto-updating images
- Revert "client: Add EventListener.SetOrdered"
- client: Add EventListener.AddChannel
- doc: Document AddChannel/RemoveChannel
- doc: Fix events table alignment
- incus/monitor: Port to EventListener.AddChannel
- incus/remote: Explain trust token prompt in verbose mode
- incus/remote: Add --tls-cert, --tls-key and --tls-p12 to remote add
- incus/remote: Move client certificates on rename
- incus/remote: Delete client certificates on removal
- i18n: Update translation templates
- incusd/cluster: Apply cluster configuration before member init
- incusd/project: Require OVN for features.networks
- doc: Update configs
- tests: Handle OVN requirement for features.networks
- incusd/instance/qmp: Use job-complete instead of block-job-complete
- incusd/instance/qemu: Use -qmp chardev instead of mon config section
- incusd/instance/qemu: Use confidential-guest-support instead of memory-encryption
- incusd/instance/qemu: Remove -mem-path and -mem-prealloc
- incusd/instance/qemu: Move sandbox configuration to qemu.conf
- incusd/instance/qemu: Move RTC configuration to qemu.conf
- incusd/instance/qemu: Move SPICE configuration to qemu.conf
- lxc: Make incremental memory migration opt-in
- storage/ceph: Ignore detached devices during RBD sysfs scan
- lxc: Normalize received CRIU state ownership
- incusd/networks: Fix panic when a network fails to start
- incusd/networks: Notify cluster members before local deletion
- incusd/cluster: Fail fast when target member is offline
- incusd/cluster: Mark offline members as unavailable for event connections
- incusd/cluster: Avoid expensive connectivity probes in NewNotifier
- incusd/cluster: Add connection timeouts to intra-cluster TLS dialer
- incusd/images: Surface write errors from compression pipeline
- incusd/instance/qemu: Cancel incoming state transfer on source failure
- client: Reconnect operation event listener on connection failure
- doc: explain how to resize virtual-machine/* volumes
- doc: storage_volumes: prefer
key=valueoverkey value - shared/subprocess: Make TryRunCommand always use C as locale
- incusd/storage/lvm: Force use of C locale everywhere isLVMNotFoundExitError is used
- incusd/storage/lvm: Check error output in isLVMNotFoundExitError
- incusd/storage/lvm: Preserve sanlock global lock on clustered pool deletion
- incusd/images: Skip offline members during image distribution
- incusd/storage: Don't query offline members in volume listing
- incusd/storage/dir: Set quota project on block volumes
- incusd/storage/dir: Set up quota when restoring custom volumes from backup
- incusd/response: Don't warn on already closed connections
- incusd/instance/qemu: Don't warn on already removed snapshot file
- incusd/instance/qemu: Return Bad Request when no NBD session is active
- shared/uefi: Implement Key#### formatting
- shared/uefi: Make formatters mandatory
- shared/uefi: Accept hexadecimal Boot#### variables
- client/oci: Move unpackOCIImage to ProtocolOCI
- gomod: Add opencontainers/image-spec
- client/oci: Strip volume mounts during unpack
- tests: Update client dependency list
- incusd/storage/drivers: Add flushBlockDeviceCache
- incusd/storage/linstor: Invalidate stale device caches on mount
- incusd/storage/linstor: Unmount volumes synchronously
- incusd/instance/qemu: Sync shared config volume during live migration
- incusd/instance/qemu: Skip config drive generation on live migration receive
- incusd/instance/qemu: Add IsLiveMigration
- incusd/device/tpm: Move swtpm control socket to the devices path
- incusd/device/tpm: Enable swtpm migration handling
- incusd/instance/qmp: Make MigrateWait event-driven
- incusd/instance/qemu: Enable migration status events
- incusd/storage: Fix source snapshot project on same-pool custom volume refresh
- incus/server/device/nic/ovn: hot-reloadable ovn nic limits
- incusd/storage/drivers/linstor: Sync filesystem instead of freezing it before snapshots
- incusd/storage: Add cleanupDependencies argument to DeleteInstanceSnapshot
- incusd/storage/drivers: Add NearLiveMigration to driver Info struct
- incusd: Add dependent disk support for in-cluster near-live migration
- incusd/instance/drivers: Add dependent disk support for in-cluster near-live migration
- tests: Add near-live migration dependent disks tests
- incusd/storage: Add skipDisks argument to GenerateDependentVolumesOffer
- incusd/instance: Add SkipDependentVolumes to MigrateSendArgs
- incusd: Add support for near-live migration for shared root storage and local dependent disks
- incusd/instances: Add non-volatileness check for NVRAM variables
- shared/uefi: Make ESL, ESLNode and ESLEntry public
- shared/uefi: Add Secure Boot vendor GUIDs
- incus/low-level: Add secureboot list subcommand
- incus/low-level: Add secureboot remove subcommand
- incus/low-level: Add secureboot add subcommand
- incus/low-level: Fix unmarshalling to nil pointer
- incus/low-level: Simplify default NVRAM list cols
- incus/low-level: Add column description for nvram list
- incus/low-level: Fix repair autocomplete
- incus/config_trust: Add full fingerprint column
- i18n: Update translation templates
- incusd/instance_post: Skip unchecked err
- golangci: Tweak static-check
- generate-database: Fix test on Go 1.27
- incusd/device: Add support for disk burst limits
- incusd/instance/drivers: Add support for disk burst limits
- tests: Add tests for disk burst limits
- doc: Add documentation for disk burst limits
- doc: Update configs
- api: device_burst_limits
- incus/query: Add --data-file flag
- i18n: Update translation templates
- incusd/device: Use network project for address set refresh on bridged NIC
- shared/uefi: Keep non-NV_VARIABLE_STORE regions
- shared/uefi: Sort GUIDs by name
- shared/uefi: Implement PlatformConfig dissector
- shared/uefi: Refactor Boot#### variable name parsing
- shared/uefi: Make Boot public
- shared/uefi: Implement BootNext dissector
- incus/start: Add --override-boot flag
- i18n: Update translation templates
- api: Add network_ipv6_ra extension
- incusd/network/bridge: Add ipv6.ra config key
- incusd/network/ovn: Add ipv6.ra config key
- doc: Update configs
- incusd/project: Add support for networks shared through restricted.networks.access
- incusd: Handle networks shared through restricted.networks.access
- incusd/device: Resolve shared networks for NIC devices
- incusd/network: Account for shared networks in usage checks
- incusd: Validate restricted.networks.access against project networks
- doc: Update configs
- tests: Add coverage for shared networks in projects
- incusd/auth: Add network shares to the authorizer interface
- incusd/auth: Add shared network support to OpenFGA
- incusd/auth: Update generated OpenFGA model
- incusd: Maintain OpenFGA network shares
- incusd: Add auth_openfga_shared_networks patch
- tests: Add OpenFGA shared network coverage
- incus/low-level: Fix unset capability of nvram set
- incusd/network/ovn: Add DeleteMACBindings
- incusd/network/ovn: Delete stale MAC bindings on instance port stop
- tests: Add NVRAM VM tests
- github: Add NVRAM VM tests job
- shared/uefi: Add getters and setters to the store
- shared/uefi: Make formatters more robust
- incusd/instances: Use new store interface
- incusd/instance/qemu: Avoid needlessly rewriting the NVRAM
- incusd/scriptlet/qemu: Add NVRAM manipulation funs
- incusd/instance/qemu: Pass NVRAM to QEMU scriptlet
- shared/scriptlet: Implement bytes (un)marshalling
- tests: Add NVRAM scriptlet test
- api: qemu_scriptlet_nvram
- doc/ref/instance_options: Update QEMU scriptlet functions
- i18n: Update translation templates
- incusd/ip: Add Addr.FlushDynamic
- incusd/device: Allow "none" NIC addresses without filtering
- incusd/forknet: Disable IPv6 autoconf on statically configured interfaces
- doc: Update configs
- incusd/ip: Add support for nic burst limits
- incusd/device: Add support for nic burst limits
- incusd/network/ovn: Add support for nic burst limits
- tests: Add tests for nic burst limits
- doc: Update configs
- api: device_burst_limits
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Tamil)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Greek)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- incusd/instance/qmp: Set a write deadline on monitor commands
- api: Add storage_ceph_rbd_backend extension
- incusd/storage/ceph: Add ceph.rbd.backend config key
- doc: Update configs
- incusd/images: Consider both architecture names when filtering
- incus/image: Consider both architecture names when filtering
- incusd: Allow recovering shared storage pools when clustered
- incus/admin: Allow recovering shared storage pools when clustered
- doc: Cover shared pool recovery on clusters
- Translated using Weblate (Portuguese)
- shared/cmd: Fix progress rendering on non-terminals
- incusd/events: Don't warn when the peer closed the connection first
- incus/network: Use global --project flag in list-allocations
- incus: Add shell completion for --project flag
- incus: Add shell completion for --target-project flag
- i18n: Update translation templates
- client: Fix event connection cleanup on listener failure
- client: Make operation reconnection more resilient
- incusd/instance/lxc: Don't fail Stop when the container stopped on its own
- incusd: Block instance creation from backup while evacuated
- incusd/cluster: Wait for ongoing instance creations before evacuating
- incusd/instance/qemu: Include stderr output in restore crash errors
- incusd/instance: Factor memory into balanced NUMA node selection
- incusd: Validate project in bulk instance state update
- incusd/cluster: Collect per-instance evacuation and restore errors
- incusd/instance/qmp: Add MigrateCancel
- incusd/instance/qemu: Treat live migration hand-over as cut-off
- incusd: Keep instance database location in sync after live migration hand-over
- shared/uefi: Add Incus GUID
- incus/low-level: Use new Incus vendor
- shared/util: Add ESLGUIDVar
- cmd/low-level: Use util.ESLGUIDVar
- shared/validate: Add IsRawNVRAMVariable and IsPEM
- incusd/instance/config: Add initial.nvram., initial.nvram-binary. and initial.secureboot.*
- doc: Update configs
- incusd/instance/qemu: Add support for NVRAM config overrides
- tests: Add NVRAM config override test
- api: instance_nvram_config
- i18n: Update translation templates
- incusd/dns: Add NOTIFY support
- incusd/network/zone: Bump SOA refresh to 15min
- incusd/network/zone: Send NOTIFY on zone and record changes
- incusd/network: Add DNSNotifyZones helper
- incusd/network/zone: Add dnsmasq file watcher
- incusd: Start network zones watcher
- incusd/network/ovn: Send NOTIFY on port and uplink changes
- incusd/networks: Send NOTIFY on network create, update and delete
- doc: Document network zone DNS NOTIFY
- incusd/instance/lxc: Fix instance directory ownership with raw.idmap
- tests: Add raw.idmap host root mapping test
- api: Add storage_cephobject_endpoint_cert extension
- incusd/storage/cephobject: Replace endpoint_cert_file with endpoint_cert
- incusd/patches: Convert cephobject.radosgw.endpoint_cert_file
- doc: Update configs
- shared/validate: Make IsPEM match anchor regexes
- Makefile: Bump minimum to Go 1.26
- gomod: Bump minimum to Go 1.26
- doc/requirements: Bump minimum to Go 1.26
- Use strings.SplitSeq to iterate over split strings
- Use new(expr) instead of protobuf pointer helpers
- Use range over int in counting loops
- Use standard library iterators
- Use strings.Builder for string concatenation
- Use fmt.Appendf
- Use errors.AsType
- Use slices.Backward for reverse iteration
- Use strings.Cut
- incusd/cgroup: Fix parse error messages
- incusd/db: Return Conflict error on duplicate storage volume record
- incusd/storage: Fix error wrapping in VolumeDBCreate
- incusd/storage/linstor: Set resource definition properties at clone time
- incusd/storage/linstor: Implement IsImageCloneSourceReady
- incusd/storage: Handle concurrent image volume creation across cluster members
- Use httputil.ReverseProxy.Rewrite
- incusd/network_integrations: Validate PEM blobs
- incusd/cluster/config: Remove unused LokiServer
- incusd/cluster/config: Validate PEM blobs
- incus/server/config: Validate PEM blobs
- doc: Update configs
- incusd/network/ovn: Allow multiple CAs
- shared/tls: Add ReadCerts
- incusd: Allow multiple CAs
- incusd/storage/linstor: Allow multiple CAs
- incusd/network/acl: Fix OVN ACL matching for cross-chassis traffic
- incusd/patches: Regenerate OVN ACL rules for address set matching
- incus/low-level: Add secureboot export subcommand
- incus/low-level: Add bundle support in secureboot add
- incus/low-level: Add secureboot import subcommand
- tests: Improve low-level secureboot coverage
- i18n: Update translation templates
- incusd/firewall/nftables: Allow EUI-64 link-local address with IPv6 filtering
- tests: Check link-local handling with IPv6 filtering
- incusd/ip: Add QdiscGeneric
- incusd/instance: Add CPUUsage
- incusd/network: Add GetTXQueueCount
- api: device_queue_disc
- incusd/device: Add support for nic queuing disciplines
- doc: Document queuing disciplines
- doc: Update configs
- tests: Add tests for nic queuing disciplines
- shared/tls: Don't duplicate issuer certificates in ACME chain
- incusd/network/ovn: Don't wait forever for database reconnection
- shared/cmd: Modernize table look
- shared/cmd: Prevent merging the last column
- tests: Reduce assumptions on list format
- doc: Use new key=value syntax
- doc: Use new table layout
- shared/uefi: Correctly handle padded VARS files
- client: Add RawQueryWithHeaders
- incus/query: Add --header flag
- test: Add test for query --header
- i18n: Update translation templates
- incus/oci: Don't URL-escape credentials in skopeo authfile
- incusd/network: Switch to backoff/v7
- incus: Switch to go-viper/mapstructure/v2
- incusd/device: Switch to gopacket/gopacket
- Update gomod
- doc/rest-api: Refresh swagger YAML
- incusd/storage/zfs: Reset host-facing properties of delegated datasets
- tests: Check properties of delegated ZFS datasets
- doc/storage/zfs: Document dataset delegation
- incusd/images: Check access before reusing cross-project image
- client/images: Prevent path traversal in downloaded image name
- Release Incus 7.4
Documentation¶
La documentation d’Incus peut être consultée sur :
https://linuxcontainers.org/incus/docs/main/
Paquets¶
Incus ne fournit pas de paquet d’installation mais bien un tarball à chaque version. Vous trouverez ci-dessous différentes solutions pour mettre Incus en service.
Installation du serveur Incus sous Linux¶
Incus est disponible sur la plupart des distributions Linux courantes. Vous trouverez des instructions d’installation détaillées dans notre documentation.
https://linuxcontainers.org/incus/docs/main/installing/
Paquet Homebrew du client Incus¶
Le client Incus est disponible sur Homebrew pour Linux et macOS.
https://formulae.brew.sh/formula/incus
Paquet Chocolatey du client Incus¶
Le client Incus est disponible sur Chocolatey pour les utilisateurs de Windows.
https://community.chocolatey.org/packages/incus/7.4.0
Paquet Winget du client Incus¶
Le client Incus est aussi disponible sur Winget pour les utilisateurs de Windows.
https://winstall.app/apps/LinuxContainers.Incus
Support¶
Les versions de fonctionnalité d’Incus ne sont supportées que jusqu’à la sortie de la suivante. Les personnes souhaitant un support plus long et des changements moins fréquents devraient plutôt envisager d’utiliser Incus 7.0 LTS.
Le support communautaire est disponible sur : https://discuss.linuxcontainers.org
Un support commercial est disponible sur : https://zabbly.com/incus
Les bugs peuvent être signalés sur : https://github.com/lxc/incus/issues
Incus 7.3 est maintenant disponible¶
31 juil. 2026
L’équipe d’Incus est heureuse d’annoncer la sortie d’Incus 7.3 !
Cette nouvelle version est assez riche, que ce soit du point de vue des nouvelles fonctionnalités, de l’amélioration des performances, de la résolution de bugs, ou encore des correctifs de sécurité.
Comme d’habitude, vous pouvez l’essayer vous-même en ligne : https://linuxcontainers.org/incus/try-it/
Correctifs de sécurité¶
Cette version corrige 13 vulnérabilités :
- CVE-2026-62867 (critique) – Argument injection through storage volume
block.create_options - CVE-2026-62940 (critique) – Project restriction bypass via instance migration config override
- CVE-2026-62941 (critique) – Project restriction bypass via cross-project instance copy
- CVE-2026-63125 (critique) – Arbitrary file write on host via
backup.yamlsymlink in crafted image - CVE-2026-63343 (critique) – Arbitrary file read+write on host via
metadata.yamlsymlink in crafted image - GHSA-26gp-p5fw-3r2h (critique) – Arbitrary file write on host via path traversal in instance backup import
- GHSA-67qw-68v3-36h6 (critique) – Arbitrary file write on host via path traversal in custom volume import
- GHSA-7fj9-65v4-rp7h (critique) – Arbitrary file write on host via image-planted symlinks and
oci.dns.*newline injection - GHSA-p2v3-6wvc-cv3p (critique) – Arbitrary file write on host via image fingerprint path traversal
- GHSA-4qxq-p5hm-3q3p (haute) – Arbitrary file read+write on host via VM template path traversal
- GHSA-m3j6-p3v3-qmjv (haute) – Container configuration newline injection through
nvidia.driver.capabilities - CVE-2026-62313 (modérée) – Project isolation restriction bypass by omitting
security.idmap.isolated - GHSA-6v6x-387m-rj4w (modérée) – Project restriction bypass on network address sets
Notez que certaines de ces vulnérabilités ne se sont pas encore vu attribuer de CVE, du fait de délais de traitement chez GitHub de 3 à 4 semaines actuellement. Nous avons demandé l’attribution de CVE pour chacunes des vulnérabilités ci-dessus ; celles-ci seront ajoutées automatiquement aux GHSA correspondantes une fois allouées.
Nouvelles fonctionnalités¶
Utilisation du contexte natif DRM dans les GPU des machines virtuelles¶
Un nouveau type de GPU, native-context, est maintenant disponible pour les machines virtuelles.
Les GPU de ce type utilisent virglrenderer et un périphérique virtio-gpu pour fournir de l’accélération 3D aux VM.
Contrairement à du passthrough GPU, la fonctionnalité permet de partager un GPU entre plusieurs VM en parallèle.
Actuellement, il semble que seul Linux a les drivers adéquats, laissant les invités Windows non accélérés.
Pour utiliser la fonctionnalité, il suffit de faire :
stgraber@vorash:~$ incus config device add v1 gpu0 gpu gputype=native-context
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_gpu/
Gestion des variables UEFI pour les machines virtuelles¶
Incus permet désormais de gérer directement la NVRAM des machines virtuelles.
Cela se fait via la commande incus low-level nvram, qui permet de manipuler la NVRAM en lecture et écriture.
La plupart des variables de la NVRAM peuvent être décomposées et mises à jour, permettant de modifier les périphériques de démarrage, leur ordre, et bien d’autres. Les opérations de modification demandent que la VM soit à l’arrêt. Une amélioration future portera sur le provisionnement de clefs Secure Boot.
De plus, une nouvelle action de réparation rebuild-nvram a été ajoutée dans incus low-level repair, simplifiant la réinitialisation de la NVRAM d’une machine dans un état sain.
stgraber@vorash:~$ incus launch images:debian/13 v1 --vm
Launching v1
stgraber@vorash:~$ incus low-level nvram get v1 Boot0000
binary: CQEAACwAQgBvAG8AdABNAGEAbgBhAGcAZQByAE0AZQBuAHUAQQBwAHAAAAAEBxQAyb24fOv4NE+q6j7kr2UWoQQGFADcW8Lu8meVTbHV+BsgOdEdf/8EAA==
data:
active: true
category: app
description: BootManagerMenuApp
force_reconnect: false
hidden: true
paths:
- - Fv(7cb8bdc9-f8eb-4f34-aaea-3ee4af6516a1)/FvFile(eec25bdc-67f2-4d95-b1d5-f81b2039d11d)
attributes:
- NON_VOLATILE
- BOOTSERVICE_ACCESS
- RUNTIME_ACCESS
Redirection de port d’instance¶
Une nouvelle commande incus port-forward simplifie l’accès à des services TCP tournant dans des instances.
L’outil en ligne de commande lance un serveur TCP local et redirige toutes les connexions vers l’adresse et le port fournis dans l’instance ou le réseau qui lui est attaché.
stgraber@vorash:~$ incus port-forward my-nginx 80 8080
stgraber@vorash:~$ incus port-forward my-nginx 10.0.3.1:443 0.0.0.0:8443
Améliorations dans la configuration des autoriseurs¶
La configuration relative à l’autorisation a été déplacée dans un nouvel ensemble de clefs authorization.*. Les anciennes clefs de configuration openfga.* sont désormais authorization.openfga.api.url, authorization.openfga.api.token et authorization.openfga.store.id. Les anciennes clefs sont automatiquement migrées lors de la mise à jour.
Cela nous permet de supporter plusieurs drivers d’autorisation en parallèle et de choisir l’un d’eux en fonction du type de requête. Le mécanisme est géré par un nouvel ensemble de clefs :
authorization.client.default: driver par défautauthorization.client.unix: driver pour les clients locaux (socketunix)authorization.client.tls: driver pour les clients TLS non restreintsauthorization.client.tls-restricted: driver pour les clients TLS restreints (liés à un projet)authorization.client.oidc: driver pour les clients authentifiés via OIDC
Chaque clef accepte allow, deny, openfga ou scriptlet, et tls pour les clients TLS restreints uniquement.
Documentation : https://linuxcontainers.org/incus/docs/main/authorization/
Nouvelle commande incus low-level¶
La commande incus debug a été renommée incus low-level.
Cette commande dispose de plusieurs sous-commandes :
bitmap(gestion des dirty bitmaps pour les VM)nvram(détaillé précédemment)repair(actions de réparation pour les instances)
Support de BGP non numéroté¶
Incus supporte à présent le BGP non numéroté pour le peering avec des routeurs externes.
Cela se fait à l’aide d’une nouvelle clef de configuration bgp.peers.NOM.interface, se substituant à bgp.peers.NOM.address.
Lorsque l’option est définie, la session est établie sur l’interface donnée en utilisant BGP non numéroté. L’adresse IPv6 de liaison locale du pair est découverte automatiquement et les routes IPv4 sont échangées via le next-hop étendu.
Documentation : https://linuxcontainers.org/incus/docs/main/howto/network_bgp/
Contrôle de la virtualisation en cascade¶
La clef de configuration d’instance security.nesting s’applique désormais aussi aux machines virtuelles.
Contrairement aux conteneurs, la valeur par défaut est true, afin de conserver le comportement antérieur.
Lorsqu’elle est définie à false, les drapeaux CPU svm et vmx sont désactivés pour la VM invitée.
Une clef de configuration de projet correspondante, restricted.virtual-machines.nesting, a également été ajoutée. Lorsqu’elle est définie à block, toutes les machines virtuelles du projet doivent avoir security.nesting défini à false.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/projects/
Liste des instances dans tous les serveurs distants¶
La commande incus list a désormais un drapeau --all-remotes, listant les instances au travers de tous les serveurs distants configurés (avec une colonne additionnelle pour le nom du serveur).
stgraber@vorash:~$ incus list --all-remotes --all-projects
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| REMOTE | PROJECT | NAME | STATE | IPV4 | IPV6 | TYPE | SNAPSHOTS | LOCATION |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| local | default | c1 | RUNNING | 10.80.1.4 (eth0) | fd42:8b9f:58e4:b6ac:1266:6aff:fe2d:7101 (eth0) | CONTAINER | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| local | default | incus-os | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| local | default | my-nginx | STOPPED | | | CONTAINER (APP) | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| local | default | v1 | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | caddy-test | STOPPED | | | CONTAINER (APP) | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | dev-os | STOPPED | | | VIRTUAL-MACHINE | 1 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | isolated-oc | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | rhel10 | RUNNING | 10.10.10.225 (eth0) | 2602:fc62:ef:1010:1266:6aff:fe69:dd25 (eth0) | CONTAINER (APP) | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | test | RUNNING | 10.226.131.1 (incusbr0) | fd42:10b9:5a70:b459::1 (incusbr0) | VIRTUAL-MACHINE | 0 | none |
| | | | | 10.10.10.73 (_venp5s0) | 2602:fc62:ef:1010:1266:6aff:fe11:9cfd (_venp5s0) | | | |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-castiana | default | v1 | RUNNING | 10.10.10.80 (enp5s0) | 2602:fc62:ef:1010:1266:6aff:fe49:20ca (enp5s0) | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-dakara | default | c1 | STOPPED | | | CONTAINER | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-dakara | default | dev-os | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-dakara | default | v1 | RUNNING | 172.17.250.222 (enp5s0) | 2602:fc62:c:250:1266:6aff:feb0:6588 (enp5s0) | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-dakara | default | win2003 | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
| s-dakara | default | win2025 | STOPPED | | | VIRTUAL-MACHINE | 0 | none |
+------------+---------+-------------+---------+-------------------------+--------------------------------------------------+-----------------+-----------+----------+
Amélioration de la gestion de l’agent des VM¶
L’agent des VM peut désormais fonctionner dans des environnement sans virtio-vsock en renvoyant des informations sur l’OS via un lien série. Cela permet a minima de récupérer la configuration IP et l’OS de la VM dans les environnements qui historiquement ne pouvaient pas lancer l’agent.
Amélioration des informations des allocations réseau¶
L’API des allocations réseau renvoie désormais le réseau auquel chaque allocation appartient.
Côté CLI, incus network list-allocations affiche une nouvelle colonne pour le réseau et dispose à présent d’un drapeau --summary pour obtenir une vue plus compacte.
stgraber@vorash:~$ incus network list-allocations
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| USED BY | ADDRESS | NETWORK | TYPE | NAT | MAC ADDRESS |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/instances/c1 | 10.80.1.4/32 | incusbr0 | instance | YES | 10:66:6a:2d:71:01 |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/instances/c1 | fd42:8b9f:58e4:b6ac:1266:6aff:fe2d:7101/128 | incusbr0 | instance | YES | 10:66:6a:2d:71:01 |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/instances/incus-os | fd42:8b9f:58e4:b6ac:1266:6aff:fef3:2d9/128 | incusbr0 | instance | YES | 10:66:6a:f3:02:d9 |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/instances/my-nginx | fd42:8b9f:58e4:b6ac:1266:6aff:fe61:8058/128 | incusbr0 | instance | YES | 10:66:6a:61:80:58 |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/instances/v1 | fd42:8b9f:58e4:b6ac:1266:6aff:fe3f:71f2/128 | incusbr0 | instance | YES | 10:66:6a:3f:71:f2 |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/networks/incusbr0 | 10.80.1.1/24 | incusbr0 | network | YES | |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
| /1.0/networks/incusbr0 | fd42:8b9f:58e4:b6ac::1/64 | incusbr0 | network | YES | |
+-------------------------+---------------------------------------------+----------+----------+-----+-------------------+
stgraber@vorash:~$ incus network list-allocations --summary
+----------+--------------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------+
| NETWORK | SUBNET | USED |
+----------+--------------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------+
| incusbr0 | 10.80.1.0/24 | 10.80.1.4 |
+----------+--------------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------+
| incusbr0 | fd42:8b9f:58e4:b6ac::/64 | fd42:8b9f:58e4:b6ac:1266:6aff:fe2d:7101, fd42:8b9f:58e4:b6ac:1266:6aff:fe3f:71f2, fd42:8b9f:58e4:b6ac:1266:6aff:fe61:8058, fd42:8b9f:58e4:b6ac:1266:6aff:fef3:2d9 |
+----------+--------------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------+
Améliorations dans les limites d’E/S¶
Les périphériques unix-block supportent désormais les clefs de configuration limits.read et limits.write, se comportant comme leurs équivalent pour les périphériques disk, et acceptant des valeurs en octets ou opérations d’E/S par seconde.
De plus, il est maintenant possible de définir à la fois des limites en octets et en opérations d’E/S par seconde sur les périphériques disk et unix-block, en les séparant par des virgules.
incus config device set my-vm data limits.read=30MiB,1000iops
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_unix_block/
Métriques sur les pools de stockage¶
L’endpoint /1.0/metrics inclut à présent les données d’utilisation des pools de stockage :
incus_storage_pool_size_bytes{pool="<pool>",driver="<driver>"}incus_storage_pool_used_bytes{pool="<pool>",driver="<driver>"}
Documentation : https://linuxcontainers.org/incus/docs/main/metrics/
Support d’ACME External Account Binding¶
L’intégration ACME supporte désormais l’External Account Binding (EAB) par l’intermédiaire de deux nouvelles clefs de configuration de serveur : acme.eab.kid et acme.eab.hmac.
Cela permet d’utiliser des fournisseurs ACME nécessitant des informations d’authentification pré-établies.
Documentation : https://linuxcontainers.org/incus/docs/main/authentication/
Informations sur les clusters de cœurs CPU dans l’API des ressources¶
L’API des ressources retourne désormais un champ cluster pour chaque cœur CPU.
C’est utile pour les environnements ARM big.LITTLE, dans lesquels les identifiants des cœurs ne sont pas uniques par socket, mais par cluster de cœurs.
L’information est visible dans incus info --resources, et est maintenant utilisée dans la logique de validation de la topologie CPU pour les VM.
Installateurs Windows et macOS natifs¶
Les nouvelles versions d’Incus disposent à présent d’installateurs natifs pour le client en ligne de commande, sous la forme d’un paquet MSI pour Windows et PKG pour macOS, construits et publiés automatiquement à chaque version.
Il est important de noter qu’aucun des installateurs n’est signé pour le moment, rendant l’installation potentiellement difficile.
Liste complète des changements¶
Voici une liste complète de tous les changements apportés par cette version :
Liste complète des commits
- cmd/incusd:
isolatedonrestricted.containers.privilegeprevents settingsecurity.privilegedtotrue - doc: regenerate configurable options index
- api: regenerate
/1.0/metadata/configurationoptions - incus/move: Apply --storage pool to dependent disks
- github: Build Windows and MacOS native installers.
- doc: fix
config setdeprectation warning - Translated using Weblate (Japanese)
- incusd/firewall: Fix double Wait in nftParseRuleset
- incusd/device: Allow static CIDR address on unmanaged bridge
- incusd/instance/qemu/qmp: Run guest memory dump detached
- incusd/instance/qemu/qmp: Add per-command timeout
- github: Add a build workflow
- build(deps): bump actions/download-artifact from 4 to 8
- build(deps): bump actions/upload-artifact from 4 to 7
- shared/logger: Add WarnOnErrorExcept helper
- incus: Avoid double-close warning on volume/bucket/instance import
- incusd/device: Reset VM disk I/O limits on unset
- incusd/devices: Allow /32 and /128 for OCI addresses
- incusd/operations: Fix nil deref race in Cancel
- cmd/generate-database/db: Manually specify uuid package
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- incusd/instance/qemu/qmp: Bump timeout for block commands
- incusd/instance/qemu/qmp: Bump timeout for slow synchronous commands
- incus/server/storage/driver/ceph: Wait, if image is already in the unpacking stage on another cluster member.
- incus: Avoid double-close warning on export and file pull
- doc/incus-cli: reword docs for configuration file path
- incusd/device/disk: Use resolved project for Ceph ISO RBD names
- incusd: Switch OCI network configuration to interfaces.json
- incusd/device: Mention "none" as valid NIC gateway value
- incusd: Support "none" gateways in OCI containers
- doc: Update configuration option metadata
- cmd/incus-agent: Implement Windows osLoadModules to check viosock service
- cmd/incus-agent: Only start agent http server if osLoadModules succeeds
- cmd/incus-agent: Write state data to ringbuffer if no http server present
- internal/server/instance/drivers/qmp: Bump ringbuffer size to 16K
- internal/server/instance/drivers/qmp: Record instance state retrieved from ringbuffer
- internal/server/instance/drivers: Treat degraded agent as offline, except when fetching state
- incusd/instance/qmp: Bump some more timeouts
- incusd: Use constant-time comparison for secrets
- incusd: Limit websocket control message size
- incusd/device: Use IsAPIName for device name validation
- incusd/storage/s3: Pin certificate for local S3 bucket transfers
- incusd/db/query: Use hex blob literal in database dumps
- incusd/instance/qemu: Use a shared memory backend on all architectures
- incusd/storage: Honor btrfs.compression on instances from optimized images
- test: Cover btrfs.compression on instances from optimized images
- incusd/storage/s3: Add GetBucketVersioning
- incus/server/storage/driver/backend: Wait, if image is already in the unpacking stage on another cluster member.
- incus/server/storage/driver/cephfs: Implement stub for IsImageCloneSourceReady function
- incus/server/storage/driver/common: Implement stub for IsImageCloneSourceReady function
- incus/server/storage/driver/linstor: Implement stub for IsImageCloneSourceReady function
- incus/server/storage/driver/lvm: Implement stub for IsImageCloneSourceReady function
- incus/server/storage/driver/truenas: Implement stub for IsImageCloneSourceReady function
- incusd/network/ovn: Add Enabled option to OVNSwitchPortOpts
- incusd/network/ovn: Add UpdateLogicalSwitchPortEnabled
- incusd/network/ovn: Add GetLogicalSwitchActivePorts
- incusd/network/ovn: Make SetLogicalSwitchQoSRules replace existing rules
- incusd/network/ovn: Extract instanceDevicePortOpts
- incusd/network/ovn: Only consider enabled switch ports as active
- incusd/network/ovn: Tweak instance port startup logic
- incusd/network/ovn: Keep instance ports until device removal
- incusd/network/ovn: Create instance ports on device add
- incusd/forknet: Wait up to 5s for initial DHCP configuration
- api: network_bgp_peer_interface
- incusd/bgp: Add support for unnumbered peers
- incusd/network: Add bgp.peers.NAME.interface
- doc: Update config
- doc/network/bgp: Document BGP unnumbered
- incusd/instance/qemu: Handle missing kvm64
- client: Only pass device overrides to sources supporting them
- incusd/instance/qemu: Serialize CPU pinning data in the CPU topology
- incusd/instance/qemu: Re-compute CPU pins on stateful start
- incusd/network/ovn: Fix NAT for network forward default targets
- incsd/device/config: Add DataFilePath field to MountEntryItem
- incusd/instance/drivers: Add support for raw-format block devices
- Translated using Weblate (Japanese)
- Translated using Weblate (Russian)
- Translated using Weblate (Swedish)
- incusd/instance: Allow security.nesting on VMs
- incusd/instance/qemu: Turn off svm and vmx when security.nesting is disabled
- api: projects_restricted_virtual_machines_nesting
- incusd/project: Add restricted.virtual-machines.nesting
- doc: Update config
- incus: Fix remote path handling on Windows
- incusd/forksyscall: Fix mknod emulation for relative paths
- internal/instance: Mention cgroup2 limitations
- doc: Update config
- incusd/auth: Move OpenFGA config to authorization.* namespace
- doc/authorization: Update for authorization config namespace
- doc: Update config
- api: authorization_config
- tests: Update OpenFGA tests for authorization config keys
- incusd/dev_incus: Fix race in ConnPidMapper access
- incusd/forksyscall: Check for path truncation in mknod emulation
- api: network_allocations_network extension
- shared/api: add Network field to NetworkAllocations
- incusd/network-allocations: populate network field
- doc/rest-api: Refresh swagger YAML
- incus/network: add --summary flag to list-allocations
- i18n: Update translation templates
- incusd/storage/ceph: Tolerate concurrently deleted RBD entities in zombie cleanup
- incusd/storage/ceph: Serialize volume deletion on the parent image
- incusd/storage/ceph: Tolerate concurrent-deletion handling for non-image parents and renames
- api: Add gpu_native_context extension
- incusd/device: Add native-context GPU device type
- incusd/instance/drivers: Support native-context GPU in QEMU
- incusd: Fix race between forkfile cleanup and respawn
- incusd/events: Don't warn on double connection close
- Translated using Weblate (Portuguese)
- incusd/apparmor: Fix alignment
- incusd/apparmor: Allow DRM render nodes for native-context GPU
- doc: Document the native-context GPU type
- doc: Update config
- incusd/linux: Add GrantPosixACLUser
- incusd/device: Grant render node access to native-context GPUs
- incusd/network/bridge: Don't NAT traffic between managed bridge networks
- incusd/storage/zfs: Clear volume quota during optimized refresh
- incusd/metrics: Add storage pool usage metric types
- incusd/metrics: Collect storage pool usage
- doc: Document storage pool metrics
- incusd/storage/zfs: Restore volume quota on refresh error
- api: Add instance_port_forward extension
- shared/api: Add InstancePortForwardPost
- client: Add GetInstancePortForwardConn
- incus-agent: Add port-forward API
- incusd/forknet: Add connect command
- incusd/instance: Add PortForwardConn
- incusd/auth: Add can_connect_tcp
- incusd/instances: Add port-forward API
- incus: Add port-forward command
- tests: Add port forward tests
- doc/rest-api: Refresh swagger YAML
- i18n: Update translation templates
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Tamil)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Greek)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Japanese)
- incusd/metrics: Rename incus_storage_pool_total_bytes to incus_storage_pool_size_bytes
- Translated using Weblate (Japanese)
- incusd/seccomp: Handle syscalls from non-leader threads
- incusd/instance/lxc: Stop the DHCP client from the stop hook
- shared/tls: Use first successful connection in RFC3493Dialer
- incusd/instances/common: Fix typo
- incusd/device: Handle CIDR values in NIC ipv4.address/ipv6.address
- incusd/network: Handle CIDR values in NIC ipv4.address/ipv6.address
- client: Only retry TLS dial on certificate verification errors
- incusd/network/ovn: Tolerate stop failures during network deletion
- incusd/device/nic_ovn: Guard cleanup against unavailable network
- incusd/networks: Run driver deletion for locally pending networks
- incusd: Honor target parameter in bitmap endpoints
- incusd/cluster: Resolve instance volumes by name in ConnectIfVolumeIsRemote
- incus/console: Escape spaces in SPICE console socket URI
- incus: Don't persist INCUS_REMOTE as the default remote
- incusd/storage/s3: Support conditional writes
- incusd/instance/qmp: Rework block job monitoring
- incusd/instance/qemu: Harden ephemeral snapshot teardown
- incusd/instance/qmp: Remove unused event channel logic
- client: Always set TLS ServerName on dial
- incusd/storage/btrfs: Restrict subvolume sources under the daemon dir
- incusd: Don't warn on double close of downloaded image files
- incus/cluster_group: Change group separator in assign subcommand
- incus/profile: Change profile separator in assign subcommand
- test: Fix assign separator
- i18n: Update translation templates
- incus/file: Fix progress reporting on stdin push
- incus/import: Fix progress reporting on stdin import
- incus/storage_bucket: Fix progress reporting on stdin import
- incus/storage_volume: Fix progress reporting on stdin import
- incus/storage_volume_file: Fix progress reporting on stdin push
- incusd/network/zone: Return a single SOA record on plain SOA queries
- incusd/storage: Fix races in connectOfflineNBD
- incusd/locking: Make unlock functions release only their own lock
- incusd/storage: Hold NBD operation lock for the whole session
- Translated using Weblate (Portuguese)
- build(deps): bump actions/setup-go from 6 to 7
- incusd/network/ovn: Detect stale database connections
- incusd/network/ovn: Remove NB client singleton
- incusd/storage: Use qcow2 virtual size as instance block size
- incusd/storage: Skip root disk size check on remote cluster move
- incusd/device: Make disk I/O limit parsing reusable
- api: Add unix_block_limits extension
- incusd/device: Add I/O limits for unix-block devices
- doc: Update config
- incusd/auth: Add allow/deny authorizers
- incusd/request: Add CtxUnixIsRoot
- incusd: Add support for multiple authorizers
- incusd: Set defaults for authorization.client.* keys
- tests: Add authorization router tests
- tests: Set authorization.client.* keys
- doc/authorization: Update for authorization client routing
- doc: Update config
- api: authorization_client_routing
- Translated using Weblate (Georgian)
- incusd/device: Require CIDR address when NIC gateway is set
- incusd/storage: Honor writable flag on offline NBD exports
- incusd/seccomp: Use namespace credentials for FUSE mounts
- incusd/dev_incus: Detect LXC monitors from cgroup v2
- incus: Rename debug subcommand to low-level and advertise it
- api: instance_nvram
- shared/api: Add InstanceNVRAMVariable struct
- shared/uefi: Add OVMF parsing primitives
- shared/uefi: Add various variable dissectors
- incusd/instance: Add GetNVRAM
- client: Add NVRAM getters
- incusd/instances: Add NVRAM API
- doc/rest-api: Refresh swagger YAML
- incus/low-level: Add nvram subcommand
- incusd/instance/qemu: Initialize NVRAM on first query
- golangci: Ignore GUID names and comments
- i18n: Update translation templates
- shared/uefi: Add some OVMF dumping primitives
- incusd/instance: Add SetNVRAM
- client: Add NVRAM variable deletion
- incusd/instances: Add NVRAM variable deletion
- doc/rest-api: Refresh swagger YAML
- incus/low-level: Add nvram unset subcommand
- i18n: Update translation templates
- api: Add disk_io_limits_combined extension
- incusd/device: Allow combining byte/s and IOPS limits
- doc/storage_volumes: Mention combined I/O limits
- doc: Update config
- Add storage note about loop devices on COW fs
- incusd/instance/lxc: Use project-qualified CRIU restore name
- incusd/instance/lxc: Clean devices after failed CRIU restore
- Translated using Weblate (Portuguese)
- incusd/storage: Fix instance copy for non-block volumes
- shared/ask: fix password prompt loop on Windows
- incusd/storage: Add support for '--refresh' for instances with dependent disks
- shared/ask: Fix newlines after functional blocks
- incusd/storage/drivers: Don't set received UUID on main btrfs volume
- incusd: Add cpus= argument to forkqemu
- incusd/instance/qemu: Confine QEMU startup to a single CPU type
- api: resources_cpu_cluster
- shared/api: Add Cluster to ResourcesCPUCore
- shared/resources: Fix CPU core grouping to handle core clusters
- incusd/instance/qemu: Make CPU topology validation cluster-aware
- incus/info: Show the CPU cluster of each core
- i18n: Update translation templates
- doc/rest-api: Refresh swagger YAML
- shared/ask: Fix static analysis
- incusd/instance/lxc: Fix OCI entrypoint escaping
- incusd/seccomp: Report FUSE mount helper failures
- incusd/storage/drivers: Fix volume activation of filesystem snapshots
- incusd/instance/qemu: Resize metadata image on disk size change
- incusd: Drop metadata image on instance copy and import
- incusd/storage: Strip unsafe symlinks in externally-supplied instance data
- incusd/storage/s3: Reject symlinks in bucket backups
- incusd/instance/qemu: Fix publish of qcow2-backed volumes
- incusd/auth: Fill missing local bucket location
- doc: Ignore bugzilla.opensuse.org in linkcheck
- Translated using Weblate (Portuguese)
- incusd/storage: Allow expected symlinks in instance metadata
- incusd/instance/qmp: Bump blockdev-add/del timeouts
- internal/filter: Prefer exact key match in ValueOf
- internal/filter: Only allow abbreviating the namespace in DotPrefixMatch
- internal/filter: Workaround spellcheck
- incus/network/allocations: Add a network column
- i18n: Update translation templates
- Translated using Weblate (Portuguese)
- incusd/cluster: Allow certificate updates with offline members on same-key renewals
- incusd/daemon: Sync cluster certificate from leader on startup
- incusd: Keep cluster listener when core.https_address changes
- incusd/firewall/nftables: Use a bridges set for cross-bridge NAT exclusions
- incusd/network/bridge: Drop the cross-bridge NAT rules refresh
- incusd/firewall: Remove unused SNATOpts.ExcludeInterfaces
- build(deps): bump KineticCafe/actions-dco from 3.1.0 to 3.2.0
- build(deps): bump actions/labeler from 6 to 7
- incusd/cgroup: Add swap accounting detection
- incusd/seccomp: Skip swap in sysinfo when swap accounting is unavailable
- incusd/instance/lxc: Handle missing swap accounting
- api: acme_eab
- shared/tls: Add EAB support to RunACMEChallenge
- incusd/cluster/config: Add acme.eab.kid and acme.eab.hmac
- incusd/acme: Pass EAB configuration to lego
- doc/authentication: Mention External Account Binding
- doc: Update config
- doc: Add EAB and HMAC to wordlist
- incusd/instance: Prevent root disk re-creation on running instances
- incusd/instance/qemu: Prevent root disk hot-unplug
- Translated using Weblate (Russian)
- Translated using Weblate (Swedish)
- incusd/instance-types: Use clouds.yaml for the list of clouds
- incusd/instance-types: Add support for root disk size
- incusd: Document HTTP 201 return code in Swagger specs
- incusd: Fix incorrect return codes in Swagger specs
- incusd/network_integrations: Return 201 with Location on rename
- incusd: Document HTTP 412 on instance and snapshot PUT/PATCH
- incusd/response: Add Conflict swagger response definition
- incusd: Document baseline error codes for endpoints using SmartError
- doc/rest-api: Refresh swagger YAML
- incusd/storage: Strip sub-path from dependent volume sources
- incusd/migration: Strip sub-path from dependent volume source overrides
- incusd/instance: Strip sub-path from dependent volume sources
- incusd: Strip sub-path from dependent volume sources
- incusd/storage: Allow unattached volumes in qcow2 migration
- incusd/instance/qmp: Add copy-before-write export helpers
- incusd/instance/qemu: Use copy-before-write overlays for NBD exports
- incusd/main_forkfile: Set SFTP max packet size to 128KiB
- incus-agent: Set SFTP max packet size to 128KiB
- internal/linux: detect initial user namespace by inode
- incus/launch: Link to the supported instance types
- doc/howto/instances_create: Update instance types link
- i18n: Update translation templates
- incusd/storage/ceph: Bound RBD unmap with a 30s timeout
- shared/archive: Add CompressionThreads
- incusd/images: Support reproducible pigz output
- shared/archive: Prefer pigz for decompression when available
- incusd/images: Prefer pigz for compression when available
- Update gomod
- client/oci: Use pgzip for image compression
- tests: Update godeps
- incusd/qemu: Use pgzip for state compression
- incus/list: Add --all-remotes
- tests: Add --all-remotes test
- i18n: Update translation templates
- client: Add ETag on NVRAM variable getter
- incusd/instances: Add ETag on NVRAM variable getter
- client: Add NVRAM variable update
- incusd/instances: Diverse fixes
- shared/api: Add InstanceNVRAMVariablePut struct
- shared/uefi: Add some OVMF formatting primitives
- incusd/instances: Add NVRAM variable update
- doc/rest-api: Refresh swagger YAML
- incus: Modify argument order in flag helpers
- incus/usage: Add MakeKV
- incus/usage: Add AsSingleton
- incus/low-level: Add nvram set subcommand
- incus/low-level: Add nvram edit subcommand
- api: instance_nvram (updated)
- i18n: Update translation templates
- incusd/firewall/nftables: Fix template race in applyNftConfig
- incusd: Fix repair endpoint swagger method
- client: Add RepairInstance
- incus/low-level: Add bitmaps subcommand
- incus/low-level: Add repair subcommand
- client: Add GetStorageVolumeBitmap
- incus/storage_volume: Add bitmap subcommand
- i18n: Update translation templates
- incusd/instance/qemu: Release operation lock on snapshot size failure
- incusd/operations: Remove operation from map on DB registration failure
- incusd: Fix goroutine leak when cluster instance list times out
- generate-database: Add ReferenceID filtering for reference tables
- incusd/db: Add ReferenceID filtering to Config and Device
- incusd/db/cluster: Update generated code
- incusd/db/cluster: Add referenced profile query helpers
- incusd/db: Only load referenced profiles when filling instances
- incusd/db/cluster: Scope profile queries in Instance.ToAPI
- incusd: Only load referenced profile data
- incusd/backup: Only load referenced profile data
- incusd/project: Scope config queries to project resources
- incusd/scriptlet: Scope instance device query
- incusd/db: Port instance config and device fill to generated queries
- incusd/instances: Add NVRAM rebuild as a repair action
- incusd/instance: Add ResetNVRAM
- api: instance_nvram (updated)
- incus/low-level: Add rebuild-nvram to the list of repair actions
- i18n: Update translation templates
- incusd/instances: Fix capitalization
- incusd/project: Restrict volume creation options in restricted projects
- internal/instance: Prevent line breaks in NVIDIA config values
- incusd/instance: Confine OCI network writes to instance root
- incusd/storage: Confine backup.yaml write to instance root
- incusd/instance: Confine metadata.yaml access to instance root
- incusd/instance/qemu: Confine template access to instance root
- incusd/images: Validate image fingerprint for all protocols
- incusd/storage: Validate volume name on ISO and backup import
- incusd/instances: Validate instance name on backup import
- incusd/instances: Re-check restrictions after copy config merge
- incusd/instance: Enforce project restrictions on migration overrides
- incusd/project: Enforce isolated restriction when idmap key omitted
- incusd: Expand network address set project for authorization
- incusd/instance: Fix NVIDIA require.cuda and require.driver handling
- incusd/instance: Confine exec-output access to its directory
- incusd: Fail closed on unknown authorization project expansion
- incusd/instance/qemu: Use os.Root for template output
- client: Make GetRawInstanceNVRAMGUIDVar return attributes
- incusd/response: Allow custom headers in devIncusResponse
- shared/uefi: Export dumpAttributes
- incusd/instances: Add headers to raw NVRAM variable response
- incus/low-level: Support more formats in NVRAM getter and setter
- i18n: Update translation templates
- Makefile: Bump to 1.25.12
- Update gomod
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Tamil)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Greek)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese)
- Release Incus 7.3
Documentation¶
La documentation d’Incus peut être consultée sur :
https://linuxcontainers.org/incus/docs/main/
Paquets¶
Incus ne fournit pas de paquet d’installation mais bien un tarball à chaque version. Vous trouverez ci-dessous différentes solutions pour mettre Incus en service.
Installation du serveur Incus sous Linux¶
Incus est disponible sur la plupart des distributions Linux courantes. Vous trouverez des instructions d’installation détaillées dans notre documentation.
https://linuxcontainers.org/incus/docs/main/installing/
Paquet Homebrew du client Incus¶
Le client Incus est disponible sur Homebrew pour Linux et macOS.
https://formulae.brew.sh/formula/incus
Paquet Chocolatey du client Incus¶
Le client Incus est disponible sur Chocolatey pour les utilisateurs de Windows.
https://community.chocolatey.org/packages/incus/7.3.0
Paquet Winget du client Incus¶
Le client Incus est aussi disponible sur Winget pour les utilisateurs de Windows.
https://winstall.app/apps/LinuxContainers.Incus
Support¶
Les versions de fonctionnalité d’Incus ne sont supportées que jusqu’à la sortie de la suivante. Les personnes souhaitant un support plus long et des changements moins fréquents devraient plutôt envisager d’utiliser Incus 7.0 LTS.
Le support communautaire est disponible sur : https://discuss.linuxcontainers.org
Un support commercial est disponible sur : https://zabbly.com/incus
Les bugs peuvent être signalés sur : https://github.com/lxc/incus/issues
Incus 7.0.1 LTS est maintenant disponible¶
10 juil. 2026
Introduction¶
L’équipe d’Incus est heureuse d’annoncer la sortie d’Incus 7.0.1 !
C’est la première version apportant des corrections de bugs pour Incus 7.0, dont le support est assuré jusqu’en juin 2031.
Pour la série de versions 7.0.x, nous découplons les nouvelles versions de correction de bugs pour nos divers projets ; il n’y aura donc pas de nouvelle version pour LXC ou LXCFS accompagnant cette nouvelle version d’Incus.
Changements¶
Comme d’habitude, cette version se concentre sur la stabilité et le hardening.
Des améliorations mineures ont également été rétroportées, en particulier tout ce qui ne nécessite pas de migrations de données, de modifications dans la base de données, ou ne cause pas de changements inattendus dans le comportement observé par l’utilisateur.
Le nombre de ces améliorations pour la branche LTS est amené à diminuer avec le temps.
Les points marquants de cette version sont :
- Reconstruction de volumes de stockage personnalisés
- Topologie CPU explicite pour les machines virtuelles
- Certificats TPM personnalisés
- Création automatique de volume
- Paramètres personnalisés pour la création de systèmes de fichiers
- Configuration LINSTOR de bas niveau
- Plages d’adresses IP dans les ensembles d’adresses réseau
- Contrôle du snooping multicast sur les bridges
- Support de plusieurs adresses par serveur distant
- Améliorations dans le stockage objet S3
- Intégration SELinux par instance
- Nouvelle commande
incus default - Informations serveur filtrées par défaut
- Définition du timeout du keepalive
- Meilleure gestion de la configuration du client sur les différents OS
- Mise à jour des certificats des serveurs non clusterisés
- Configuration réseau statique pour les conteneurs OCI
- Annonce de routes en BGP par instance
- Adresses dynamiques pour les proxys en mode NAT
- Accès NBD étendu
- Compression btrfs pour les volumes de stockage
- Configuration des GUID des VF InfiniBand en SR-IOV
- Restriction de l’origine des websockets
Cette mise à jour corrige également les vulnérabilités suivantes :
- CVE-2026-48753 (critique) – Arbitrary file write via path traversal in S3 multipart upload
- CVE-2026-47753 (faible) – Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)
- CVE-2026-48754 (faible) – Nil-pointer dereference in createDependentVolumesFromBackup
- CVE-2026-48756 (faible) – Nil-pointer dereference in CreateCustomVolumeFromBackup
- CVE-2026-48749 (critique) – Arbitrary file read+write on host via
rootfs/symlink in malicious image - CVE-2026-48750 (critique) – Arbitrary file write on host via
exec-outputsymlink in crafted image - CVE-2026-48751 (critique) – Restricted project bypass leading to arbitrary command execution
- CVE-2026-48752 (critique) – Arbitrary file read+write on host via
templates/symlink in malicious image - CVE-2026-48755 (critique) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
- CVE-2026-48769 (critique) – Arbitrary file write on client due to trusted image hash
- CVE-2026-55621 (haute) – Project restriction bypass for custom volume copy across projects
- CVE-2026-55622 (haute) – Project restriction bypass in instance copy across projects
Toutes ces vulnérabilités ont déjà été corrigées dans les précédentes versions mensuelles d’Incus, et leurs correctifs ont déjà été rétroportés par les diverses distributions fournissant Incus 7.0 LTS.
La liste complète des commits est présentée ci-dessous :
Liste détaillée des changements
- doc/devices/disk: Fix broken link
- incusd/instance/qemu: Fix version detection for qemu-kvm
- incusd: Re-introduce core scheduling detection
- incusd/instance/lxc: Fix swap=false failure
- incusd/forknet: Persist DHCPv6 client DUID across restarts
- incusd/forknet: Include FQDN in DHCPv6 INFO requests
- incusd/forknet: Properly renew stateful DHCPv6
- incusd/forknet: Add jitter to DHCPv6 renewal
- incusd/device/nic_bridged: Fix swapped IPv4/IPv6 DNS record
- doc/authorization: Fix reference to old "manager" relation
- incusd/network/acl: Fix issue with instances in different project than ACL
- incusd/projects: Fix targeting on project delete
- incusd/storage_volume_nbd: Fix incorrect swagger
- doc/rest-api: Refresh swagger YAML
- test/network_acl: Add test for ACL used by instance in different project
- incusd/instance/qemu: Remove deprecated QEMU flag
- incusd/cluster: Re-order evacuations to happen earlier on shutdown
- incusd/endpoints: Fix Wait() race in Tomb shutdown
- incusd/instance/qemu: Pass SMBIOS type 11 entries via files
- incusd/db/node: Cleanup node offline messages
- api: network_bridge_multicast_snooping
- incusd/network/bridge: Add bridge.multicast_snooping config key
- doc: Update config
- incusd/locking: Add TryLock
- incusd/storage: Use InstanceByVolumeName in qcow2MigrateVolume
- incusd/storage: Add lock handling for NBD operations
- devcontainer: fix golangci-lint install source
- build(deps): bump actions/dependency-review-action from 4 to 5
- incusd/storage/drivers: Restore config volume as part of VM block restoration
- doc: Update Ansible section with incus-client details
- Update list of Ubuntu LTS releases that get pre-built Incus packages
- Use correct host:port format for ClusterAddress
- incusd/cluster: Better handle misisng OVS/OVN
- incusd/storage/zfs: Avoid recursive zfs list in GetResources
- incusd/network/ovn: Skip per-IP NAT for external routes when no uplink
- incusd/instances: Skip offline members in bulk state changes
- incusd/instance/drivers/lxc: Quote values in lxc.environment
- test: Disable volume shrinking with LINSTOR
- doc/storage_volume: Fix outdated information
- incusd/storage/s3: Implement S3 CopyObject
- incus/storage_volume: Add --create flag to attach
- tests/storage_volume_attach: Test --create on attach
- incusd/storage/s3: Implement ACL placeholder
- tests/storage: Add S3 CopyObject coverage
- incusd/storage/drivers: Add workaround for shared VG removal failures
- incusd/networks: Parallelize network startup and OVN restart
- incusd/ip: Set NUD_PERMANENT on neighbour proxy entries
- incusd/device/nic_bridged: Drop redundant accept_ra=0
- incusd/device/nic_bridged: Recover orphaned veth on startup
- incusd/forknet: Use space separator for DNS search domains
- incusd/db/node: Allow using a fixed time in Offline checks
- incus: Print console log when attaching via --console
- incusd/storage/ceph: Refuse pool deletion when unexpected images exist
- shared/api: Fix swagger examples
- cmd/incus: Clarify --expiry flag format
- doc: Clarify snapshots.expiry
- doc: Update metadata
- doc/rest-api: Refresh swagger YAML
- incusd/firewall/nftables: Use terse mode to improve performance
- client/oci: Pass --no-tags to skopeo inspect
- incus/server/network/ovn/driver: Fix duplicate listening ip check in ForwardCreate
- incus/server/network/ovn/driver: Fix duplicate listening ip check in LoadBalancerCreate
- Extend description for OCI-compliant remotes
- incusd/instance/qmp: Add QueryVirtioVGADevice
- incusd/instance/qemu: Add virtio vga feature gating
- incus/operation: Fix default column layout in help text
- incus/network: Fix typo in description
- incus/network/zone: Align long and short descriptions
- incus/network: Fix typo in description
- incus/storage/volume: Fix typo in description
- incus/config/trust: Fix typo in description
- incus/network/forward: Fix typo in description
- incus/image: Align description formatting
- incus/config/trust: Align description formatting
- incus/warning: Align description formatting
- incus/cluster/group: Fix typo in description
- incus/project: Fix typo in description
- incus/project: Align description formatting
- incus/storage/volume: Align long and short description
- api: storage_create_options
- incusd/storage/drivers: Add support for block.create_options
- tests: Add test for block.create_options
- doc: Update config
- incus/utils: Tweak environment file handling to strip matching outer quotes
- shared/archive: Improved ENOSPC detection
- api: instances_tpm_platform_cert
- incusd/devices: Set volatileGet on Refresh
- incusd/cluster/config: Add instances.tpm.platform keys
- incusd/device/tpm: Provision vTPM with platform CA when configured
- doc: Update config
- doc: Add PEM to wordlist
- incus/cluster: Fix typo in description
- incus/launch: Clarify examples
- incus/remote_unix: Clarify socket type
- incus/network/forward: Fix typo in description
- incus/launch: Update examples
- incus/config: Fix YAML file name in help text
- shared/simplestreams: Add combined_type
- incus-simplestreams: Support split container images
- incus-simplestreams: Detect type of unified images
- incusd/forknet: Time out DHCPv4 lease acquisition
- incusd/forknet: Time out DHCPv6 lease acquisition
- incusd/forknet: Handle zero wait time for DHCPv6
- incusd/forknet: Filter the DHCPv4 raw socket
- Makefile: Use older incus-os for Go 1.25
- gomod: Update dependencies
- incusd/storage: Allow skipping validation for more prefixes
- incusd/storage/linstor: Allow setting raw DRBD properties on storage pools
- incusd/storage/linstor: Allow setting raw DRBD properties on storage volumes
- tests: Add quick raw DRBD key checks
- api: linstor_raw
- incusd/network/ovn: Use dnat_and_snat for fully mapped external addresses
- doc: Update config
- api: network_address_set_ip_ranges
- incusd/network/address-set: Support IP ranges
- doc: Document IP range support in network address sets
- tests: Add IP range coverage for network address sets
- inucsd/devices/tpm: Enable tpm live migration
- incusd/storage/zfs: Use latest common GUID as refresh base
- incusd/instances: Only reset NVRAM on secureboot change for VMs
- incus/file: Fix push behavior with UID/GID/mode overrides
- incus/file: Fix typo
- tests: Add thorough tests for incus file push with UID/GID/mode overrides
- incus/storage_volume: Fix push behavior with UID/GID/mode overrides
- incus/info: Handle negative usage values (unknown)
- incusd/storage: Return -1 as disk usage when the driver doesn't support it
- incusd/instance: Handle negative disk usage values
- incusd/instance/lxc: Use os.Root for templating
- tests: Update btrfs test for new behavior
- incusd/storage: Add missing doc comments on exported symbols (revive:exported)
- incusd/storage: Rename locals that shadow imports (revive:import-shadowing)
- incusd/storage: Simplify if/else with early return (revive:early-return)
- incusd/storage: Check type assertion result (revive:unchecked-type-assertion)
- incusd/storage: Use tagged switch statements (staticcheck:QF1003)
- incusd/storage: Simplify boolean with De Morgan's law (staticcheck:QF1001)
- incusd/storage/drivers: Add missing doc comments on exported symbols (revive:exported)
- incusd/storage/drivers: Rename locals that shadow imports (revive:import-shadowing)
- incusd/storage/drivers: Avoid deferring inside loops (revive:defer)
- incusd/storage/drivers: Simplify if/else with early return (revive:early-return)
- incusd/storage/drivers: Remove extra blank lines at start of block (revive:empty-lines)
- incusd/storage/drivers: Omit inferable type from declaration (staticcheck:QF1011)
- incusd/storage/drivers: Use strings.Split instead of SplitN (staticcheck:QF1004)
- incusd/storage/drivers: Use tagged switch statements (staticcheck:QF1003)
- incusd/network/ovs: Remove unused unquote function (unused)
- incusd/network/ovs: Use strings.Split instead of SplitN (staticcheck:QF1004)
- incusd/network/ovn: Use tagged switch statements (staticcheck:QF1003)
- incusd/network/zone: Rename param that shadows state import (revive:import-shadowing)
- incusd/network/zone: Add and fix doc comments on exported methods (revive:exported)
- incusd/network/acl: Rename locals that shadow imports (revive:import-shadowing)
- incusd/network/acl: Use tagged switch on rule.Action (staticcheck:QF1002)
- incusd/network/acl: Use tagged switch on rule.Protocol (staticcheck:QF1003)
- incusd/network/acl: Merge conditional assignment into declaration (staticcheck:QF1007)
- incusd/network/acl: Invert condition to return early (revive:early-return)
- incusd/network/acl: Remove blank line at start of switch (revive:empty-lines)
- incusd/network: Add and fix doc comments on exported symbols (revive:exported)
- incusd/network: Rename locals that shadow imports (revive:import-shadowing)
- incusd/network: Remove blank line at start of block (revive:empty-lines)
- incusd/network: Remove embedded common field from selectors (staticcheck:QF1008)
- incusd/network: Merge conditional assignment into declaration (staticcheck:QF1007)
- incusd/network: Lift break condition into loop (staticcheck:QF1006)
- incusd/network: Use tagged switch statements (staticcheck:QF1003)
- incusd/operations: Add missing doc comments on exported methods (revive:exported)
- incusd/operations: Rename param that shadows import (revive:import-shadowing)
- incusd/endpoints: Rename locals that shadow import (revive:import-shadowing)
- incusd/cluster: Drop redundant client import alias (revive:redundant-import-alias)
- incusd/cluster: Add missing doc comments on exported methods (revive:exported)
- incusd/cluster: Simplify with early return (revive:early-return)
- incusd/cluster: Avoid deferring inside loops and chains (revive:defer)
- incusd/cluster: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db/query: Add missing doc comments on exported symbols (revive:exported)
- incusd/db/query: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db/node: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db/schema: Check error from db.Close (errcheck)
- incusd/db/schema: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db/cluster: Remove redundant import alias (revive:redundant-import-alias)
- incusd/db/cluster: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db/cluster: Check type assertion result (revive:unchecked-type-assertion)
- incusd/db/cluster: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd/db: Rename locals that shadow imports (revive:import-shadowing)
- incusd/db: Apply De Morgan's law to simplify boolean (staticcheck:QF1001)
- incusd/db: Rename profileIds parameter to profileIDs (revive:var-naming)
- incusd/db: Rename local that redefines builtin max (revive:redefines-builtin-id)
- incusd/db: Check type assertion result (revive:unchecked-type-assertion)
- incusd/db: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd/db: Omit redundant types in var declarations (revive:var-declaration)
- incusd/db: Add space after comment delimiter (revive:comment-spacings)
- incusd/db: Omit type from strings.Builder declarations (staticcheck:ST1023)
- incusd/logging: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd/instance/drivers/qmp: Fix doc comment on exported Run method (revive:exported)
- incusd/instance/drivers/qmp: Use tagged switch statement (staticcheck:QF1003)
- incusd/instance: Return explicit values instead of bare returns (revive:bare-return)
- incusd/instance: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd/instance: Rename locals that shadow imports (revive:import-shadowing)
- incusd/instance/drivers: Remove unused const and function (unused)
- incusd/instance/drivers: Remove unnecessary blank line at end of block (whitespace)
- incusd/instance/drivers: Omit inferred type from var declaration (revive:var-declaration)
- incusd/instance/drivers: Avoid deferring inside loops (revive:defer)
- incusd/instance/drivers: Return early to reduce nesting (revive:early-return)
- incusd/instance/drivers: Check type assertions (revive:unchecked-type-assertion)
- incusd/instance/drivers: Add doc comments on exported methods (revive:exported)
- incusd/instance/drivers: Rename locals that shadow imports (revive:import-shadowing)
- incusd/instance/drivers: Replace append loop with variadic append (staticcheck:S1011)
- incusd/instance/drivers: Use tagged switch statements (staticcheck:QF1003)
- incus: Use tagged switch statement (staticcheck:QF1003)
- incus: Remove unused functions (unused)
- incus/usage: Remove dead assignments to renderedAtoms (staticcheck:SA4006)
- incusd/dns: Add doc comment on exported method ServeDNS (revive:exported)
- incusd/dns: Rename param that shadows db import (revive:import-shadowing)
- incusd/dnsmasq: Use strings.Split instead of SplitN (staticcheck:QF1004)
- incusd/dnsmasq/dhcpalloc: Lift break condition into loop (staticcheck:QF1006)
- incusd/metrics: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd/scriptlet: Use tagged switch statements (staticcheck:QF1003)
- incusd/scriptlet/log: Fix doc comment on exported CreateLogger (revive:exported)
- incusd/ucred: Check type assertion in GetConnFromContext (revive:unchecked-type-assertion)
- incusd/refcount: Omit redundant type in var declaration (revive:var-declaration)
- incusd/metadata: Add doc comment on exported var Data (revive:exported)
- incusd/firewall/drivers: Remove unused subnetMask function (unused)
- incusd/bgp: Remove unused setup method (unused)
- incusd/config: Use fmt.Fprintf instead of WriteString (staticcheck:QF1012)
- incusd: Fix import grouping (gci)
- incusd: End comments with a period (godot)
- incusd: Remove unnecessary trailing newline (whitespace)
- incusd: Merge conditional assignments into declarations (staticcheck:QF1007)
- incusd: Convert byte slice argument to string (staticcheck:QF1010)
- incusd: Use fmt.Fprintf instead of Write of Sprintf (staticcheck:QF1012)
- incusd: Fix errors.Is argument order (staticcheck:SA1032)
- incusd: Remove dead source connection (staticcheck:SA4006)
- incusd: Use tagged switch statements (staticcheck:QF1003)
- incusd: Fix identifier naming (revive:var-naming)
- incusd: Rename locals that shadow imports (revive:import-shadowing)
- incusd: Use comma-ok form for type assertions (revive:unchecked-type-assertion)
- incusd: Return early to reduce nesting (revive:early-return)
- incusd: Drop else after return (revive:indent-error-flow)
- incusd: Avoid deferring inside loops (revive:defer)
- incusd: Add space after comment delimiter (revive:comment-spacings)
- incusd: Rename local that shadows builtin min (revive:redefines-builtin-id)
- incusd: Remove empty else block (revive:empty-block)
- incusd: Remove blank line at start of block (revive:empty-lines)
- incusd: Remove useless break in case clauses (revive:useless-break)
- incusd: Annotate intentional os.Exit calls (revive:deep-exit)
- incusd: Fix remaining identifier naming (revive:var-naming)
- incusd/device/config: Rename copy locals that shadow builtin (revive:redefines-builtin-id)
- incusd/response: Add doc comments on exported Render methods (revive:exported)
- incusd/response: Avoid defer inside loop in fileResponse.Render (revive:defer)
- incusd/response: Use fmt.Fprintf instead of WriteString with Sprintf (staticcheck:QF1012)
- incusd/events: Remove embedded Conn field from selectors (staticcheck:QF1008)
- incusd/events: Add doc comments on exported methods (revive:exported)
- incusd/auth: Rename locals that shadow logger import (revive:import-shadowing)
- incusd/auth: Add doc comments on exported symbols (revive:exported)
- incusd/auth: Use strings.Split instead of SplitN (staticcheck:QF1004)
- incusd/auth/oidc: Check email claim type assertion (revive:unchecked-type-assertion)
- incusd/auth/oidc: Add doc comments on exported methods (revive:exported)
- incusd/device: Rename locals that shadow imports (revive:import-shadowing)
- incusd/device: Avoid defer inside loop in checkAttachedRunningProcesses (revive:defer)
- incusd/device: Remove blank line at start of block (revive:empty-lines)
- incusd/device: Remove unnecessary blank line in validateConfig (whitespace)
- incusd/device: Invert conditions to return early (revive:early-return)
- incusd/device: Check container type assertions (revive:unchecked-type-assertion)
- incusd/device: Remove embedded StorageVolume field from selector (staticcheck:QF1008)
- incusd/device: Apply De Morgan's law to simplify booleans (staticcheck:QF1001)
- incusd/device: Use tagged switch statements (staticcheck:QF1003)
- internal/linux: Return error last from GetErrno (revive:error-return)
- internal/linux: Rename devpts_fd parameter (revive:var-naming)
- internal/linux: Drop redundant = nil from err declaration (revive:var-declaration)
- internal/linux: Add missing doc comments on exported symbols (revive:exported)
- incusd/apparmor: Add doc comment on nullWriteCloser.Close (revive:exported)
- incusd/apparmor: Omit inferred type from strings.Builder declarations (staticcheck:ST1023)
- incusd/backup: Rename locals that shadow state import (revive:import-shadowing)
- incusd/seccomp: Simplify setxattr whiteout check with early return (revive:early-return)
- incusd/fsmonitor: Rename local that shadows logger import (revive:import-shadowing)
- incusd/fsmonitor/drivers: Rename locals that shadow logger import (revive:import-shadowing)
- incusd/fsmonitor/drivers: Add doc comments on exported Name methods (revive:exported)
- incusd: Add newline after block before switch case (newline-after-block)
- incusd/device: Add newline after block before switch case (newline-after-block)
- incusd/instance/drivers: Add newline after block before switch case (newline-after-block)
- incusd/storage/drivers: Add newline after block before switch case (newline-after-block)
- incus: Add newline after block before switch case (newline-after-block)
- incus: Inline reflect.Ptr as reflect.Pointer (govet:inline)
- incusd/operations: Inline reflect.Ptr as reflect.Pointer (govet:inline)
- incusd: Omit redundant error type from sentinel var declaration (revive:var-declaration)
- incusd/cluster: Omit redundant error type from sentinel var declaration (revive:var-declaration)
- incusd/dnsmasq/dhcpalloc: Omit redundant error type from sentinel var declaration (revive:var-declaration)
- incusd/instance/operationlock: Omit redundant error type from sentinel var declaration (revive:var-declaration)
- test/lint: Run full golangci-lint instead of only new changes
- api: storage_volumes_rebuild
- incusd/storage: Add RebuildCustomVolume to pool backend
- shared/api: Add StorageVolumeRebuildPost
- incusd/storage: Add storage volume rebuild API endpoint
- doc/rest-api: Refresh swagger YAML
- client: Add RebuildStoragePoolVolume
- incus/storage_volume: Add rebuild command
- tests: Add storage volume rebuild test
- incusd/network/ovn: Correctly set VLAN on uplink veth
- incusd/network/physical: Skip VLAN interface on filtered bridges
- incusd: Rename dqlite references to cowsql
- global: Use sync.WaitGroup.Go for goroutine management
- global: Use maps.Copy instead of manual copy loops
- global: Use range-over-int loops
- global: Use reflect.TypeFor
- global: Use t.Context in tests
- incusd: Use unsafe.Add for pointer arithmetic in forkproxy
- incusd/instance/drivers: Use the min builtin for memory capping
- global: Use strings.Cut instead of strings.Split/SplitN
- global: Use strings.CutSuffix instead of HasSuffix/TrimSuffix
- global: Use slices.Backward for reverse iteration
- shared/api: Drop no-op omitempty on nested struct fields
- global: Use strings.Builder for string concatenation in loops
- incus/remote: Add support for multiple URLs
- incus: Refactor calls to the parser
- incus: Remove global mutable state from the parser
- incus: Keep track of last working remote
- doc: Update command name
- incus/storage/s3: Support SigV4 presigned URLs
- incus/storage/s3: Support SigV2 presigned URLs
- tests: Add storage bucket presigned URL test
- client: handle absolute paths for simplestream files
- shared/api/url: Add URL fragment setter
- incusd/storage: Improve handling of daemon volumes
- incusd/db/cluster/entities: Add TypeServer and fix map sorting
- incusd/project: Handle server objects
- api: api_fragments
- incusd/storage: Prevent creating daemon volumes on shared pools
- incusd/images: Revert 36f513c
- incus/remote: Improve usage
- incus/storage/volume: Improve usage
- incus/move: Improve usage
- incus/image: Improve usage
- incus/config: Fix typo in usage
- incusd/devices: Cleanup leftover forkproxy on startup
- incus/storage_volume: Put big subcommands into their own files
- incus/file: Make recursive push apply UID/GID overrides recursively
- tests: Switch to recursive chown on file push
- api: instance_limits_cpu_topology
- shared/validate: Add CPU topology parsing helper
- internal/instance: Allow CPU topology syntax for limits.cpu
- incusd/instance: Support CPU topology for VM limits.cpu
- doc: Document CPU topology support for limits.cpu
- doc: Update config
- incusd/instance/drivers: Apply standard API object name checks
- incusd/device: Encode device names in DevicesPath storage paths
- incusd/storage: Fix unsafe access to backup data
- incusd/storage: Guard nil ExpiresAt in CreateCustomVolumeFromBackup
- incusd/storage: Guard nil fields in createDependentVolumesFromBackup
- incusd/storage/s3: Confine multipart uploads with os.Root
- internal/instance: Add volatile.last_state.agent
- internal/server: fire agent events after checking current state
- doc: Update config
- tests: Update for new name restrictions
- incusd/instance/lxc: Allow unsetting limits.memory.swap without hitting a cgroup error
- incusd/instance/drivers: Round memory hotplug size up to block size
- gomod: Update dependencies
- doc/authorization: Fix markdownlint
- shared/tls: Add support for Lego v5
- incusd/instance/lxc: Fix environment quoting
- incusd/storage/zfs: Refuse refresh only when snapshots have no common base
- shared/tls: Detect Lego version/behavior based on help
- doc/cloud-init: Clarify VM behavior
- github: Remove pre-installed java
- incus: Make unset commands accept several keys
- server/network: fix comment alignment
- server/network: fix scope of node specific network configs
- doc: update generated metadata
- server/metadata: update generated metadata
- internal/server/instance/drivers: Add migration-compatible hv flags with migration.stateful=true
- cmd/generate-database/db: Add joinas db tag
- cmd/generate-database/lex: Fix pluralizations ending in y
- incusd/storage: Fix qcow2 custom volume backups
- incusd/instance/qemu: Remove stale migrate.sock before qcow2 export
- incusd/response: Abort piped exports that fail mid-stream
- incusd/migration: Detect target migration errors
- incusd/instance/qemu: Tweak migration fallback for VMs
- incusd: Reject migration onto existing instance of different type
- incusd/migrate: Bump migration handshake timeouts to 2 minutes
- shared/api: Remove legacy logic
- incusd/cluster: Remove legacy logic
- Update gomod
- incusd: Use partial device validation when recovering instances
- incusd/network/ovn: Don't require an active chassis when updating tunnels
- incusd/network: Clean up stale OVS ports on startup
- incusd/cluster: Honor cluster group during evacuation
- incusd/cluster: Honor restricted cluster groups during evacuation
- incusd/cluster: Improve evacuation and restoration progress reporting
- global: Clean latest gofumpt
- incusd: Replace gorilla/mux with http.ServeMux
- Update go.mod
- api: instance_nbd
- client: Add GetInstanceNBDConn
- incusd/instances: Add NBD API
- incusd/storage: Implement all-disks NBD function
- incusd/instance/qmp: Add block snapshot transaction and node size helpers
- incusd/instance: Implement ConnectNBDAllDisks
- incusd/instance/qemu: Use empty NBD export name for single-disk exports
- incusd/instance/qemu: Report disk usage on stopped instances
- incus/debug: Add NBD command
- doc/rest-api: Refresh swagger YAML
- incusd/instance/drivers/qmp: Add locking around event handlers
- incusd/instance/qemu: Fully cleanup the old monitor
- incusd/storage/drivers: Handle sgdisk return codes
- incusd/auth/oidc: Refactor cookie setting logic
- shared/api: Add Server.Filtered()
- incus/info: Add --show-sensitive
- incusd/auth/oidc: Set expiration on authentication cookies
- incusd/auth/oidc: Clear cookies on terminal refresh failure
- shared/logger: Add WarnOnError helper
- incusd/instancewriter: Log deferred errors with WarnOnError
- incus: Log deferred errors with WarnOnError
- incus-agent: Log deferred errors with WarnOnError
- internal/incusos: Log deferred errors with WarnOnError
- internal/linux: Log deferred errors with WarnOnError
- incusd/migration: Log deferred errors with WarnOnError
- internal/netutils: Log deferred errors with WarnOnError
- internal/rsync: Log deferred errors with WarnOnError
- incusd/backup: Log deferred errors with WarnOnError
- incusd/cgroup: Log deferred errors with WarnOnError
- incusd/cluster: Log deferred errors with WarnOnError
- incusd/device: Log deferred errors with WarnOnError
- incusd/device/pci: Log deferred errors with WarnOnError
- incusd/dnsmasq: Log deferred errors with WarnOnError
- incusd/firewall/drivers: Log deferred errors with WarnOnError
- incusd/instance/drivers: Log deferred errors with WarnOnError
- incusd/network: Log deferred errors with WarnOnError
- incusd/network/acl: Log deferred errors with WarnOnError
- incusd/response: Log deferred errors with WarnOnError
- incusd/seccomp: Log deferred errors with WarnOnError
- incusd/storage: Log deferred errors with WarnOnError
- incusd/storage/quota: Log deferred errors with WarnOnError
- incusd/storage/s3: Log deferred errors with WarnOnError
- incusd/storage/s3/local: Log deferred errors with WarnOnError
- incusd/util: Log deferred errors with WarnOnError
- internal/util: Log deferred errors with WarnOnError
- incusd: Log deferred errors with WarnOnError
- incusd/storage/drivers: Log deferred errors with WarnOnError
- client: Log deferred errors with WarnOnError
- incusd/db: Log deferred errors with WarnOnError
- incusd/db/cluster: Log deferred errors with WarnOnError
- incusd/db/node: Log deferred errors with WarnOnError
- incusd/db/query: Log deferred errors with WarnOnError
- incusd/db/schema: Log deferred errors with WarnOnError
- shared/resources: Log deferred errors with WarnOnError
- shared/resources/usbid: Log deferred errors with WarnOnError
- shared/idmap: Log deferred errors with WarnOnError
- shared/cliconfig: Log deferred errors with WarnOnError
- shared/archive: Log deferred errors with WarnOnError
- shared/subprocess: Log deferred errors with WarnOnError
- shared/simplestreams: Log deferred errors with WarnOnError
- shared/util: Log deferred errors with WarnOnError
- incus-migrate: Log deferred errors with WarnOnError
- incus-benchmark: Log deferred errors with WarnOnError
- incus-user: Log deferred errors with WarnOnError
- incus-simplestreams: Log deferred errors with WarnOnError
- lxc-to-incus: Log deferred errors with WarnOnError
- generate-database/file: Log deferred errors with WarnOnError
- incusd: Rename forknet logger parameter to avoid shadowing
- incusd: Log deferred errors in main_forknet with WarnOnError
- github: Update DCO check
- incusd/api_internal: Add server-certificate endpoint
- incus/admin: Add update-certificate command
- i18n: Update translation templates
- incusd/device/disk: Use virtiofsd --posix-acl=auto if supported
- incus/client: Fix panic when cancelling
- incus/remote: Move OIDC and cookie jar on rename
- incus/cluster: Document the actions
- incusd/console: Read the container console without resetting it
- incusd/linux: Add DialUnix helper
- incusd/qemu: Handle long run paths for the QMP socket
- incusd/qemu: Handle long run paths for the SPICE socket
- shared/cliconfig: Remove duplicate file closing
- Makefile: Remove pinned incus-os
- Update gomod
- global: Update for go-yaml/v4 rc5
- incus/alias: Add alias add command examples with args and numbered args
- doc/incus-alias: Fix italic and ref modifers order to correctly apply both modifiers
- Makefile: Fix sphinx build script to prevent issues with terminal colors
- doc/incus-alias: Refactor doc to create new use-case section and provide how-to examples
- incus/debug: Fix NBD description
- client: Add reuse support to GetInstanceNBDConn
- incusd/instance/qmp: Add listen path support to NBDServerStart
- incusd/instance/qmp: Allow multiple NBD server connections
- incusd/instance/qemu: Update NBDServerStart calls
- incusd/instance: Add reuse support to ConnectNBDAllDisks
- incusd/storage: Add reuse support to GetInstanceAllDisksNBD
- incusd/instances: Add NBD reuse parameter
- incus/debug: Support multiple NBD client connections
- doc/rest-api: Refresh swagger YAML
- incus/server/storage/driver/ceph: Shrink images to minimal size after unpacking
- doc/incus-cli: Add CLI configuration file reference
- Makefile: add incremental spellcheck that skips the sphinx and cli setups
- Makefile: Improve target padding in make help
- incusd/linux: Add ListenUnix helper
- incusd/qemu: Handle long run paths for the migration socket
- incusd/qemu: Handle long run paths for the console socket
- incusd/qemu: Handle long run paths for the virtiofs socket
- incusd/images: Mention images available for other instance types
- incusd/device/nic_routed: Add neighbour proxy entries on the on-link interface
- incusd/network/ovn: Don't use missing router IP as DNS server
- doc: Update preseed description to match with reality
- incus/utils_copy: Fix wrong error returned
- doc: Ignore criu.org link checking
- api: network_bridge_bgp_instances
- incusd/network: Add BGP instance advertisement config keys
- incusd/device: Advertise individual instance addresses over BGP
- doc: Document BGP advertisement of instance addresses
- doc: Update config
- doc: Add NIC's to wordlist
- incusd: Use IsNoneOrEmpty helper
- incusd/device: Add configOrVolatile helper
- incus/remote: Add set-keepalive subcommand
- incus/keepalive: Fix comment typo
- doc/remote: Update docs with keepalive configuration via CLI commands
- incus/alias: Fix wrong example command typo
- api: core_https_allowed_websocket_origin
- shared/ws: Validate websocket origin against trusted origins
- incusd: Add core.https_allowed_websocket_origin server config key
- doc: Update config
- incus: close web UI probe response body
- ci: authenticate OpenFGA release lookups
- storage/zfs: factor out send receive helper
- storage/zfs: avoid raw sends for encrypted snapshot copies
- tests: cover encrypted ZFS snapshot copies
- incus/server/storage/driver/volume: Ensure cached image can grow to needed size and not be restricted by pool size config.
- tests: Add more tests for ConfigSizeFromSource
- doc: Update AI/LLM policy
- doc: Add GPG to wordlist
- client: Default to port 443 for raw connections
- incusd/util: Fix JWT validation
- api: Add storage_btrfs_compression extension
- incusd/storage/drivers: Add "btrfs.compression" volume option
- doc: Document the "btrfs.compression" volume option
- doc: Update config
- doc/rest-api: Refresh swagger YAML
- incus/server/storage/driver/ceph: Don't return error if image size is larger than cached image size
- build(deps): bump actions/checkout from 6 to 7
- incusd/instance/lxc: Restrict OCI configuration keys to OCI containers
- api: Add oci_network_config extension
- internal/instance: Simplify OCI key descriptions
- internal/instance: Add OCI DNS configuration keys
- incusd/device: Apply OCI static network configuration on NICs
- incusd/instance/lxc: Generate OCI container network files
- incusd/main_forknet: Handle static interfaces and DNS in forknet dhcp
- doc: Update config
- incusd/storage/btrfs: Fix daemon dir prefix check
- doc/cloud-init: Change YAML spec domain
- incus/server/device: Persist NIC host_name before creating interface
- incusd/images: Tolerate concurrent image record creation in a cluster
- incus/events: Forward info-level log events across the cluster
- incus/vm: Select OVMF.amdsev.fd firmware for SEV guests
- incus/vm: Skip vmcoreinfo device for SEV guests
- incus/console: Ignore not-exist error when removing temporary socket
- github: Block LLM/AI attribution in commit messages
- incusd: Skip br_netfilter proxy/forward handling on IncusOS
- incusd/storage/zfs: Batch snapshot GUID lookups
- incusd/endpoints: Fix infinite loop in network error log writer
- api: infiniband_sriov_guid
- incusd/ip: Add SetVfNodeGUID/SetVfPortGUID for SR-IOV
- incusd/device/infiniband: Add configurable port_guid/node_guid for SR-IOV
- doc: Update config
- doc: Add GUID to wordlist
- incusd/storage/lvm: Account for qcow2 overhead in volume sizing
- incusd/storage: Add patch to fix existing lvmcluster qcow2 volumes
- incusd: Skip NVRAM setup for unified AMD SEV firmware
- shared/cliconfig: Use platform-specific config directory
- incus: Use platform-specific cache directory
- incusd/device/disk: Reject pool property with special sources
- incusd/network/bridge: Clarify nat.order has no effect on nftables
- incusd/metadata: Update generated metadata
- shared/osinfo: Add osinfo package
- internal/server/instance/drivers: Use DetermineOS and osinfo.OSType for instance GuestOS value
- internal/server/instance/drivers: Update GuestOS usages
- internal/server/instance/drivers: Add OS version specific QEMU options
- incusd/storage/drivers: Apply nodatacow directly for btrfs.compression=none
- incusd/storage/drivers: Allow btrfs.compression as a pool-wide default
- test: Cover btrfs.compression nodatacow and pool-wide default
- incusd/network: Add GetNeighbourAddresses helper
- incusd/device: Add shared instance neighbour scan helper
- incusd/firewall: Allow wildcard listen address in proxy NAT
- incusd/device: Support dynamic addresses in proxy NAT mode
- doc: Update config
- doc: Document proxy NAT dynamic addresses
- tests: Add proxy NAT wildcard and dynamic address tests
- incusd: Rename neighbour to neighbor for US english
- incusd: Reject rootfs symlink for instances
- incusd/exec: Reject exec-output symlink
- incusd/instance: Enforce project restrictions on snapshot restore
- api: instance_selinux
- internal/server/sys: Extend SELinux context detection
- internal/server/selinux: Add SELinux package
- shared/validate: Add SELinux validation functions
- internal/instance: Add SELinux configuration keys
- internal/server/project: Add SELinux config permissions
- incusd: Rename forkstart to forklxc and forklimits to forkqemu
- incusd: Add SELinux exec context to forkqemu
- internal/server/instance/drivers: Add SELinux support
- doc: Update config
- Update gomod
- incusd/instance: Confine template access to instance root
- shared/validate: Reject compression algorithm arguments
- incusd/images: Validate fingerprint on direct download
- incusd/storage: Check source volume access on copy
- incusd/instances: Check source instance access on copy
- incus/default: Add incus default commands
- cmd/incusd:
isolatedonrestricted.containers.privilegeprevents settingsecurity.idmap.isolatedtofalse - doc: regenerate configurable options index
- api: regenerate
/1.0/metadata/configurationoptions - incusd/storage: Recreate missing snapshot config subvolume
- incusd/storage: Fix storage patches
- incus: Fix gofumpt
- cmd/incusd:
isolatedonrestricted.containers.privilegeprevents settingsecurity.privilegedtotrue - doc: regenerate configurable options index
- api: regenerate
/1.0/metadata/configurationoptions - doc: fix
config setdeprectation warning - incusd/firewall: Fix double Wait in nftParseRuleset
- incusd/device: Allow static CIDR address on unmanaged bridge
- shared/logger: Add WarnOnErrorExcept helper
- incus: Avoid double-close warning on volume/bucket/instance import
- incusd/device: Reset VM disk I/O limits on unset
- incusd/devices: Allow /32 and /128 for OCI addresses
- incusd/operations: Fix nil deref race in Cancel
- cmd/generate-database/db: Manually specify uuid package
- incus: Avoid double-close warning on export and file pull
- doc/incus-cli: reword docs for configuration file path
- incusd/device/disk: Use resolved project for Ceph ISO RBD names
- incusd: Use constant-time comparison for secrets
- incusd: Limit websocket control message size
- incusd/device: Use IsAPIName for device name validation
- incusd/storage/s3: Pin certificate for local S3 bucket transfers
- incusd/db/query: Use hex blob literal in database dumps
- incusd/storage: Honor btrfs.compression on instances from optimized images
- test: Cover btrfs.compression on instances from optimized images
- incusd/storage/s3: Add GetBucketVersioning
- incusd/instance/qemu: Handle missing kvm64
- client: Only pass device overrides to sources supporting them
- incusd/instance/qemu: Serialize CPU pinning data in the CPU topology
- incusd/instance/qemu: Re-compute CPU pins on stateful start
- incus: Fix remote path handling on Windows
- incusd/forksyscall: Fix mknod emulation for relative paths
- internal/instance: Mention cgroup2 limitations
- doc: Update config
- incusd/dev_incus: Fix race in ConnPidMapper access
- incusd/forksyscall: Check for path truncation in mknod emulation
- i18n: Update translation templates
- Makefile: Bump to Go 1.25.11
- Update gomod
Support et mise à niveau¶
La branche Incus 7.0 est supportée jusqu’en juin 2031.
Il est toujours fortement recommandé d’utiliser la dernière version de correction de bugs.
Téléchargements¶
- Tarball d’Incus : incus-7.0.1.tar.xz
- Signature GPG : incus-7.0.1.tar.xz.asc
Incus 7.2 est maintenant disponible¶
26 juin 2026
L’équipe d’Incus est heureuse d’annoncer la sortie d’Incus 7.2 !
Cette nouvelle version comporte bon nombre de nouvelles fonctionnalités très diverses, accompagnées d’améliorations de performances et de résolutions de bugs.
Comme d’habitude, vous pouvez l’essayer vous-même en ligne : https://linuxcontainers.org/incus/try-it/
Correctifs de sécurité¶
Cette version corrige 8 vulnérabilités :
- CVE-2026-48749 (critique) – Arbitrary file read+write on host via
rootfs/symlink in malicious image - CVE-2026-48750 (critique) – Arbitrary file write on host via
exec-outputsymlink in crafted image - CVE-2026-48751 (critique) – Restricted project bypass leading to arbitrary command execution
- CVE-2026-48752 (critique) – Arbitrary file read+write on host via
templates/symlink in malicious image - CVE-2026-48755 (critique) – Argument injection in backup compression algorithm leading to arbitrary file write and command execution
- CVE-2026-48769 (critique) – Arbitrary file write on client due to trusted image hash
- CVE-2026-55621 (haute) – Project restriction bypass for custom volume copy across projects
- CVE-2026-55622 (haute) – Project restriction bypass in instance copy across projects
Nouvelles fonctionnalités¶
Intégration SELinux par instance¶
Incus supporte maintenant le confinement SELinux par instance, pour les conteneurs et les machines virtuelles, avec allocation automatique de catégories MCS (Multi-Category Security) pour isoler les instances les unes des autres sur un même hôte.
Quatre nouvelles clefs de configuration pour les instances ont été ajoutées :
security.selinux.domain: force le domaine de processus SELinuxsecurity.selinux.type: force le type de fichier SELinux utilisé pour le stockage de l’instancesecurity.selinux.level: force le niveau MCS SELinuxsecurity.selinux.label_rootfs: contrôle le comportement de la labellisation du rootfs (auto,alwaysounever)
Le contexte calculé est stocké dans la clef de configuration volatile.selinux.context, de sorte que la plage MCS allouée reste stable au redémarrage.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/instance_options/#instance-options-security
Nouvelle commande incus default¶
Une nouvelle commande, incus default, a été ajoutée afin de contrôler les options par défaut de l’outil en ligne de commande.
stgraber@orilla:~$ incus default show
list_format: ""
console_type: ""
console_spice_command: ""
no_color: false
stgraber@orilla:~$ incus default set list_format=compact
stgraber@orilla:~$ incus storage list
NAME DRIVER DESCRIPTION USED BY STATE
default zfs 11 CREATED
stgraber@orilla:~$ incus default unset list_format
stgraber@orilla:~$ incus storage list
+---------+--------+-------------+---------+---------+
| NAME | DRIVER | DESCRIPTION | USED BY | STATE |
+---------+--------+-------------+---------+---------+
| default | zfs | | 11 | CREATED |
+---------+--------+-------------+---------+---------+
stgraber@orilla:~$
La documentation de ces options a également été mise à jour :
https://linuxcontainers.org/incus/docs/main/client-config/
Informations serveur filtrées par défaut¶
incus info retourne désormais une vue filtrée des informations du serveur.
Cela a pour effet de masquer par défaut (en les remplaçant par SENSITIVE) tous les certificats, clefs privées, et autres jetons, ne les affichant que si --show-sensitive est passé. Le retour de la commande est également plus court, dans la mesure où la liste complète des extensions d’API n’est plus affichée, la remplaçant par un simple compteur.
Définition du timeout du keepalive¶
La commande incus remote a désormais une sous-commande set-keepalive pour configurer (ou désactiver) le timeout du keepalive de la connexion.
stgraber@orilla:~$ incus remote set-keepalive my-remote 30
stgraber@orilla:~$ incus remote set-keepalive my-remote 0
La fonctionnalité est utilisée pour maintenir une connexion avec un serveur distant, rendant les interactions suivantes plus rapides. Elle est particulièrement utile sur les connexions à forte latence, ainsi que dans les environnements où beaucoup de commandes incus sont lancées.
Meilleure gestion de la configuration du client sur les différents OS¶
L’outil en ligne de commande stocke désormais sa configuration et son cache dans un répertoire mieux adapté vis-à-vis de l’OS client.
Jusqu’à présent, le client utilisait ~/.config/incus/ et ~/.cache/incus/, peu importe le système d’exploitation, répertoires peu communs pour macOS et Windows.
Depuis Incus 7.2, macOS utilise ~/Library/Application Support/incus/ et Windows utilise %APPDATA%\incus. Le client déplacera automatiquement sa configuration au premier lancement.
Mise à jour des certificats des serveurs non clusterisés¶
Une nouvelle commande incus admin update-certificate permet de remplacer le certificat d’un serveur non clusterisé.
La commande est équivalente à incus cluster update-certificate, mais pour les serveurs hors cluster. Cela permet d’éviter de remplacer à la main les fichiers dans /var/lib/incus.
Configuration réseau statique pour les conteneurs OCI¶
Le réseau des conteneurs d’application OCI peut désomais être configuré statiquement.
Les clefs de configuration pour les interfaces réseau ipv4.address et ipv6.address acceptent à présent des sous-réseaux CIDR pour configurer les adresses des conteneurs, et les nouvelles clefs ipv4.gateway et ipv6.gateway définissent la passerelle par défaut. Lorsque l’une de ces adresses est définie à none, cela désactive la configuration de la famille d’adresses correspondante et empêche le lancement du client DHCP.
En ce qui concerne le DNS, les nouvelles clefs de configuration d’instance oci.dns.nameservers, oci.dns.domain et oci.dns.search permettent de définir le contenu initial du fichier resolv.conf des conteneurs, lequel est ensuite complété par les informations reçues en DHCP.
Ces clefs de configuration sont uniquement valides pour les conteneurs OCI.
stgraber@orilla:~$ incus create docker:nginx my-nginx
Creating my-nginx
stgraber@orilla:~$ incus config set my-nginx oci.dns.nameservers=1.0.0.1,1.1.1.1 oci.dns.domain=stgraber.net
stgraber@orilla:~$ incus config device override my-nginx eth0 ipv4.address=10.10.10.2/24 ipv4.gateway=10.10.10.1
Device eth0 overridden for my-nginx
stgraber@orilla:~$ incus start my-nginx
stgraber@orilla:~$ incus list my-nginx
+----------+---------+-------------------+------------------------------------------------+-----------------+-----------+
| NAME | STATE | IPV4 | IPV6 | TYPE | SNAPSHOTS |
+----------+---------+-------------------+------------------------------------------------+-----------------+-----------+
| my-nginx | RUNNING | 10.10.10.2 (eth0) | fd42:8b9f:58e4:b6ac:1266:6aff:fecb:e324 (eth0) | CONTAINER (APP) | 0 |
+----------+---------+-------------------+------------------------------------------------+-----------------+-----------+
Annonce de routes en BGP par instance¶
Les réseaux bridge gérés par Incus ont deux nouvelles clefs de configuration, bgp.ipv4.instances et bgp.ipv6.instances.
Lorsque ces options sont activées, Incus annonce une route /32 (IPv4) ou /128 (IPv6) en BGP pour chaque instance connectée au réseau, supprimant la route lorsque l’instance s’arrête. Cela simplifie le routage des instances dans les environnements BGP.
Dans le cadre de cette nouvelle fonctionnalité, Incus peut à présent apprendre les adresses IP des instances, en surveillant les paquets ARP/NDP pendant une courte période suivant leur démarrage.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/network_bridge/
Adresses dynamiques pour les proxys en mode NAT¶
Incus étant à présent capable de détecter les adresses IP des instances, les périphériques proxy en mode NAT peuvent désormais utiliser des adresses dynamiques, supprimant la nécessité d’indiquer manuellement les adresses des instances dans la configuration du proxy.
stgraber@orilla:~$ incus launch docker:nginx my-nginx
Launching my-nginx
stgraber@orilla:~$ incus config device add my-nginx http-80 proxy listen=tcp:0.0.0.0:1234 connect=tcp:0.0.0.0:80 nat=true
Device http-80 added to my-nginx
stgraber@orilla:~$ incus list my-nginx
+----------+---------+--------------------+------------------------------------------------+-----------------+-----------+
| NAME | STATE | IPV4 | IPV6 | TYPE | SNAPSHOTS |
+----------+---------+--------------------+------------------------------------------------+-----------------+-----------+
| my-nginx | RUNNING | 10.80.1.162 (eth0) | fd42:8b9f:58e4:b6ac:1266:6aff:fe55:dbdb (eth0) | CONTAINER (APP) | 0 |
+----------+---------+--------------------+------------------------------------------------+-----------------+-----------+
stgraber@orilla:~$ ip -4 a show dev enp0s5
2: enp0s5: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
altname enx001c42e6a809
inet 10.211.55.3/24 brd 10.211.55.255 scope global dynamic noprefixroute enp0s5
valid_lft 1031sec preferred_lft 1031sec
stgraber@orilla:~$ nc -v 10.211.55.3 1234
Connection to 10.211.55.3 1234 port [tcp/*] succeeded!
Accès NBD étendu¶
Un nouvel endpoint, GET /1.0/instances/{instance}/nbd, expose en NBD tous les disques attachés à une machine virtuelle, permettant un accès concurrent à tous les disques plutôt que volume par volume.
Cela a mené à la création d’une nouvelle commande incus debug nbd, supportant des connexions concurrentes.
stgraber@orilla:~$ incus start v1
stgraber@orilla:~$ incus debug nbd v1
NBD listening on 127.0.0.1:36539
Ces API sont principalement à destination des systèmes de sauvegarde ayant besoin d’accéder aux disques des VM. L’export NBD expose également les dirty bitmaps, simplifiant l’implémentation de sauvegardes incrémentales.
La restauration peut être effectuée via les API NBD de chaque volume lorsque l’instance est arrêtée.
Compression btrfs pour les volumes de stockage¶
Une nouvelle clef de configuration de volume de stockage, btrfs.compression, a été ajoutée pour le driver btrfs. Il correspond à la propriété compression de btrfs, et accepte les mêmes valeurs (par exemple, zstd, lzo, zlib ou none).
Cela permet de forcer les paramètres de compression pour un système de fichiers btrfs, permettant aux volumes Incus d’utiliser un différent algorithme de compression, ou aucun, ce qui permet alors à Incus de définir le drapeau nocow pour les disques des machines virtuelles.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/storage_btrfs/
Configuration des GUID des VF InfiniBand en SR-IOV¶
Les périphériques infiniband utilisant le nictype sriov supportent désormais deux nouvelles clefs de configuration, node_guid et port_guid.
Lorsque l’une des clefs est définie, son GUID correspondant est défini à cette valeur pour la fonction virtuelle allouée au démarrage de l’instance, puis est restauré à sa valeur initiale à l’arrêt de celle-ci.
Documentation : https://linuxcontainers.org/incus/docs/main/reference/devices_infiniband/
Restriction de l’origine des websockets¶
Une nouvelle clef de configuration de serveur, core.https_allowed_websocket_origin, a été ajoutée.
Elle accepte une liste d’origines séparées par des virgules, ou *, et contrôle quelles origines sont acceptées pour les connexions en websocket.
Cela est utile pour les accès cross-origin et dans certains environnements proxifiés.
Documentation : https://linuxcontainers.org/incus/docs/main/server_config/#server-options-core
Journalisation des routines de nettoyage¶
Un changement apporté à l’ensemble du code d’Incus dans cette nouvelle version journalise les erreurs retournées par les fonctions de nettoyage appelées de manière asynchrone.
En conséquence, un certain nombre d’entrées WARNING pourront être constatées (par exemple à la fermeture de fichiers, sockets, ou réponses HTTP). Cet effet est attendu et n’indique pas de régression ; les erreurs existaient déjà auparavant, mais étaient tout simplement ignorées.
Si vous remarquez des messages inutiles ou répétitifs, merci de nous le faire savoir, afin que nous puissions investiguer, et si nécessaire les passer sous silence.
Liste complète des changements¶
Voici une liste complète de tous les changements apportés par cette version :
Liste complète des commits
- Translated using Weblate (Greek)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Tamil)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese)
- doc/authorization: Fix markdownlint
- shared/tls: Add support for Lego v5
- incusd/instance/lxc: Fix environment quoting
- incusd/storage/zfs: Refuse refresh only when snapshots have no common base
- shared/tls: Detect Lego version/behavior based on help
- doc/cloud-init: Clarify VM behavior
- github: Remove pre-installed java
- incus: Make unset commands accept several keys
- i18n: Update translation templates
- server/network: fix comment alignment
- server/network: fix scope of node specific network configs
- doc: update generated metadata
- server/metadata: update generated metadata
- internal/server/instance/drivers: Add migration-compatible hv flags with migration.stateful=true
- cmd/generate-database/db: Add joinas db tag
- cmd/generate-database/lex: Fix pluralizations ending in y
- Translated using Weblate (Portuguese)
- incusd/storage: Fix qcow2 custom volume backups
- incusd/instance/qemu: Remove stale migrate.sock before qcow2 export
- incusd/response: Abort piped exports that fail mid-stream
- incusd/migration: Detect target migration errors
- incusd/instance/qemu: Tweak migration fallback for VMs
- incusd: Reject migration onto existing instance of different type
- incusd/migrate: Bump migration handshake timeouts to 2 minutes
- Remove lxd-to-incus
- shared/api: Remove legacy logic
- incusd/cluster: Remove legacy logic
- Update gomod
- incusd: Use partial device validation when recovering instances
- incusd/network/ovn: Don't require an active chassis when updating tunnels
- incusd/network: Clean up stale OVS ports on startup
- incusd/cluster: Honor cluster group during evacuation
- incusd/cluster: Honor restricted cluster groups during evacuation
- incusd/cluster: Improve evacuation and restoration progress reporting
- global: Clean latest gofumpt
- incusd: Replace gorilla/mux with http.ServeMux
- Update go.mod
- api: instance_nbd
- client: Add GetInstanceNBDConn
- incusd/instances: Add NBD API
- incusd/storage: Implement all-disks NBD function
- incusd/instance/qmp: Add block snapshot transaction and node size helpers
- incusd/instance: Implement ConnectNBDAllDisks
- incusd/instance/qemu: Use empty NBD export name for single-disk exports
- incusd/instance/qemu: Report disk usage on stopped instances
- incus/debug: Add NBD command
- i18n: Update translation templates
- doc/rest-api: Refresh swagger YAML
- incusd/instance/drivers/qmp: Add locking around event handlers
- incusd/instance/qemu: Fully cleanup the old monitor
- incusd/storage/drivers: Handle sgdisk return codes
- incusd/auth/oidc: Refactor cookie setting logic
- shared/api: Add Server.Filtered()
- incus/info: Add --show-sensitive
- i18n: Update translation templates
- incusd/auth/oidc: Set expiration on authentication cookies
- incusd/auth/oidc: Clear cookies on terminal refresh failure
- shared/logger: Add WarnOnError helper
- incusd/instancewriter: Log deferred errors with WarnOnError
- incus: Log deferred errors with WarnOnError
- incus-agent: Log deferred errors with WarnOnError
- internal/incusos: Log deferred errors with WarnOnError
- internal/linux: Log deferred errors with WarnOnError
- incusd/migration: Log deferred errors with WarnOnError
- internal/netutils: Log deferred errors with WarnOnError
- internal/rsync: Log deferred errors with WarnOnError
- incusd/backup: Log deferred errors with WarnOnError
- incusd/cgroup: Log deferred errors with WarnOnError
- incusd/cluster: Log deferred errors with WarnOnError
- incusd/device: Log deferred errors with WarnOnError
- incusd/device/pci: Log deferred errors with WarnOnError
- incusd/dnsmasq: Log deferred errors with WarnOnError
- incusd/firewall/drivers: Log deferred errors with WarnOnError
- incusd/instance/drivers: Log deferred errors with WarnOnError
- incusd/network: Log deferred errors with WarnOnError
- incusd/network/acl: Log deferred errors with WarnOnError
- incusd/response: Log deferred errors with WarnOnError
- incusd/seccomp: Log deferred errors with WarnOnError
- incusd/storage: Log deferred errors with WarnOnError
- incusd/storage/quota: Log deferred errors with WarnOnError
- incusd/storage/s3: Log deferred errors with WarnOnError
- incusd/storage/s3/local: Log deferred errors with WarnOnError
- incusd/util: Log deferred errors with WarnOnError
- internal/util: Log deferred errors with WarnOnError
- incusd: Log deferred errors with WarnOnError
- incusd/storage/drivers: Log deferred errors with WarnOnError
- client: Log deferred errors with WarnOnError
- incusd/db: Log deferred errors with WarnOnError
- incusd/db/cluster: Log deferred errors with WarnOnError
- incusd/db/node: Log deferred errors with WarnOnError
- incusd/db/query: Log deferred errors with WarnOnError
- incusd/db/schema: Log deferred errors with WarnOnError
- shared/resources: Log deferred errors with WarnOnError
- shared/resources/usbid: Log deferred errors with WarnOnError
- shared/idmap: Log deferred errors with WarnOnError
- shared/cliconfig: Log deferred errors with WarnOnError
- shared/archive: Log deferred errors with WarnOnError
- shared/subprocess: Log deferred errors with WarnOnError
- shared/simplestreams: Log deferred errors with WarnOnError
- shared/util: Log deferred errors with WarnOnError
- incus-migrate: Log deferred errors with WarnOnError
- incus-benchmark: Log deferred errors with WarnOnError
- incus-user: Log deferred errors with WarnOnError
- incus-simplestreams: Log deferred errors with WarnOnError
- lxc-to-incus: Log deferred errors with WarnOnError
- generate-database/file: Log deferred errors with WarnOnError
- incusd: Rename forknet logger parameter to avoid shadowing
- incusd: Log deferred errors in main_forknet with WarnOnError
- github: Update DCO check
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Greek)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Tamil)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Portuguese)
- incusd/api_internal: Add server-certificate endpoint
- incus/admin: Add update-certificate command
- i18n: Update translation templates
- incusd/device/disk: Use virtiofsd --posix-acl=auto if supported
- Translated using Weblate (Russian)
- Translated using Weblate (Swedish)
- Translated using Weblate (Portuguese)
- incus/client: Fix panic when cancelling
- incus/remote: Move OIDC and cookie jar on rename
- incus/cluster: Document the actions
- incusd/console: Read the container console without resetting it
- incusd/linux: Add DialUnix helper
- incusd/qemu: Handle long run paths for the QMP socket
- incusd/qemu: Handle long run paths for the SPICE socket
- i18n: Update translation templates
- shared/cliconfig: Remove duplicate file closing
- Makefile: Remove pinned incus-os
- Update gomod
- global: Update for go-yaml/v4 rc5
- Translated using Weblate (Portuguese)
- Translated using Weblate (Swedish)
- Translated using Weblate (Russian)
- incus/alias: Add alias add command examples with args and numbered args
- doc/incus-alias: Fix italic and ref modifers order to correctly apply both modifiers
- Makefile: Fix sphinx build script to prevent issues with terminal colors
- doc/incus-alias: Refactor doc to create new use-case section and provide how-to examples
- i18n: Update translation templates
- incus/debug: Fix NBD description
- i18n: Update translation templates
- client: Add reuse support to GetInstanceNBDConn
- incusd/instance/qmp: Add listen path support to NBDServerStart
- incusd/instance/qmp: Allow multiple NBD server connections
- incusd/instance/qemu: Update NBDServerStart calls
- incusd/instance: Add reuse support to ConnectNBDAllDisks
- incusd/storage: Add reuse support to GetInstanceAllDisksNBD
- incusd/instances: Add NBD reuse parameter
- incus/debug: Support multiple NBD client connections
- i18n: Update translation templates
- doc/rest-api: Refresh swagger YAML
- incus/server/storage/driver/ceph: Shrink images to minimal size after unpacking
- doc/incus-cli: Add CLI configuration file reference
- Makefile: add incremental spellcheck that skips the sphinx and cli setups
- Makefile: Improve target padding in make help
- incusd/linux: Add ListenUnix helper
- incusd/qemu: Handle long run paths for the migration socket
- incusd/qemu: Handle long run paths for the console socket
- incusd/qemu: Handle long run paths for the virtiofs socket
- incusd/images: Mention images available for other instance types
- incusd/device/nic_routed: Add neighbour proxy entries on the on-link interface
- incusd/network/ovn: Don't use missing router IP as DNS server
- doc: Update preseed description to match with reality
- incus/utils_copy: Fix wrong error returned
- doc: Ignore criu.org link checking
- api: network_bridge_bgp_instances
- incusd/network: Add BGP instance advertisement config keys
- incusd/device: Advertise individual instance addresses over BGP
- doc: Document BGP advertisement of instance addresses
- doc: Update config
- doc: Add NIC's to wordlist
- incusd: Use IsNoneOrEmpty helper
- incusd/device: Add configOrVolatile helper
- incus/remote: Add set-keepalive subcommand
- incus/keepalive: Fix comment typo
- doc/remote: Update docs with keepalive configuration via CLI commands
- incus/alias: Fix wrong example command typo
- i18n: Update translation templates
- api: core_https_allowed_websocket_origin
- shared/ws: Validate websocket origin against trusted origins
- incusd: Add core.https_allowed_websocket_origin server config key
- doc: Update config
- incus: close web UI probe response body
- ci: authenticate OpenFGA release lookups
- storage/zfs: factor out send receive helper
- Translated using Weblate (Greek)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (German)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Georgian)
- Translated using Weblate (Georgian)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (Spanish)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (French)
- Translated using Weblate (Tamil)
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Chinese (Simplified Han script))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Portuguese (Brazil))
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Norwegian Bokmål)
- Translated using Weblate (Dutch)
- Translated using Weblate (Dutch)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Swedish)
- Translated using Weblate (Italian)
- Translated using Weblate (Italian)
- Translated using Weblate (Russian)
- Translated using Weblate (Russian)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Japanese)
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Chinese (Traditional Han script))
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- Translated using Weblate (Indonesian)
- storage/zfs: avoid raw sends for encrypted snapshot copies
- tests: cover encrypted ZFS snapshot copies
- incus/server/storage/driver/volume: Ensure cached image can grow to needed size and not be restricted by pool size config.
- tests: Add more tests for ConfigSizeFromSource
- doc: Update AI/LLM policy
- doc: Add GPG to wordlist
- Translated using Weblate (Swedish)
- Translated using Weblate (Portuguese)
- Translated using Weblate (Russian)
- client: Default to port 443 for raw connections
- incusd/util: Fix JWT validation
- api: Add storage_btrfs_compression extension
- incusd/storage/drivers: Add "btrfs.compression" volume option
- doc: Document the "btrfs.compression" volume option
- doc: Update config
- doc/rest-api: Refresh swagger YAML
- incus/server/storage/driver/ceph: Don't return error if image size is larger than cached image size
- build(deps): bump actions/checkout from 6 to 7
- incusd/instance/lxc: Restrict OCI configuration keys to OCI containers
- api: Add oci_network_config extension
- internal/instance: Simplify OCI key descriptions
- internal/instance: Add OCI DNS configuration keys
- incusd/device: Apply OCI static network configuration on NICs
- incusd/instance/lxc: Generate OCI container network files
- incusd/main_forknet: Handle static interfaces and DNS in forknet dhcp
- doc: Update config
- incusd/storage/btrfs: Fix daemon dir prefix check
- doc/cloud-init: Change YAML spec domain
- incus/server/device: Persist NIC host_name before creating interface
- incusd/images: Tolerate concurrent image record creation in a cluster
- incus/events: Forward info-level log events across the cluster
- incus/vm: Select OVMF.amdsev.fd firmware for SEV guests
- incus/vm: Skip vmcoreinfo device for SEV guests
- incus/console: Ignore not-exist error when removing temporary socket
- github: Block LLM/AI attribution in commit messages
- incusd: Skip br_netfilter proxy/forward handling on IncusOS
- incusd/storage/zfs: Batch snapshot GUID lookups
- incusd/endpoints: Fix infinite loop in network error log writer
- api: infiniband_sriov_guid
- incusd/ip: Add SetVfNodeGUID/SetVfPortGUID for SR-IOV
- incusd/device/infiniband: Add configurable port_guid/node_guid for SR-IOV
- doc: Update config
- doc: Add GUID to wordlist
- incusd/storage/lvm: Account for qcow2 overhead in volume sizing
- incusd/storage: Add patch to fix existing lvmcluster qcow2 volumes
- incusd: Skip NVRAM setup for unified AMD SEV firmware
- shared/cliconfig: Use platform-specific config directory
- incus: Use platform-specific cache directory
- incusd/device/disk: Reject pool property with special sources
- incusd/network/bridge: Clarify nat.order has no effect on nftables
- incusd/metadata: Update generated metadata
- shared/osinfo: Add osinfo package
- internal/server/instance/drivers: Use DetermineOS and osinfo.OSType for instance GuestOS value
- internal/server/instance/drivers: Update GuestOS usages
- internal/server/instance/drivers: Add OS version specific QEMU options
- incusd/storage/drivers: Apply nodatacow directly for btrfs.compression=none
- incusd/storage/drivers: Allow btrfs.compression as a pool-wide default
- test: Cover btrfs.compression nodatacow and pool-wide default
- incusd/network: Add GetNeighbourAddresses helper
- incusd/device: Add shared instance neighbour scan helper
- incusd/firewall: Allow wildcard listen address in proxy NAT
- incusd/device: Support dynamic addresses in proxy NAT mode
- doc: Update config
- doc: Document proxy NAT dynamic addresses
- tests: Add proxy NAT wildcard and dynamic address tests
- incusd: Rename neighbour to neighbor for US english
- incusd: Reject rootfs symlink for instances
- incusd/exec: Reject exec-output symlink
- incusd/instance: Enforce project restrictions on snapshot restore
- api: instance_selinux
- internal/server/sys: Extend SELinux context detection
- internal/server/selinux: Add SELinux package
- shared/validate: Add SELinux validation functions
- internal/instance: Add SELinux configuration keys
- internal/server/project: Add SELinux config permissions
- incusd: Rename forkstart to forklxc and forklimits to forkqemu
- incusd: Add SELinux exec context to forkqemu
- internal/server/instance/drivers: Add SELinux support
- doc: Update config
- Update gomod
- incusd/instance: Confine template access to instance root
- shared/validate: Reject compression algorithm arguments
- incusd/images: Validate fingerprint on direct download
- incusd/storage: Check source volume access on copy
- incusd/instances: Check source instance access on copy
- incus/default: Add incus default commands
- i18n: Update translation templates
- cmd/incusd:
isolatedonrestricted.containers.privilegeprevents settingsecurity.idmap.isolatedtofalse - doc: regenerate configurable options index
- api: regenerate
/1.0/metadata/configurationoptions - incusd/storage: Recreate missing snapshot config subvolume
- Translated using Weblate (Portuguese)
- incusd/storage: Fix storage patches
- incus: Fix gofumpt
- i18n: Update translation templates
Documentation¶
La documentation d’Incus peut être consultée sur :
https://linuxcontainers.org/incus/docs/main/
Paquets¶
Incus ne fournit pas de paquet d’installation mais bien un tarball à chaque version. Vous trouverez ci-dessous différentes solutions pour mettre Incus en service.
Installation du serveur Incus sous Linux¶
Incus est disponible sur la plupart des distributions Linux courantes. Vous trouverez des instructions d’installation détaillées dans notre documentation.
https://linuxcontainers.org/incus/docs/main/installing/
Paquet Homebrew du client Incus¶
Le client Incus est disponible sur Homebrew pour Linux et macOS.
https://formulae.brew.sh/formula/incus
Paquet Chocolatey du client Incus¶
Le client Incus est disponible sur Chocolatey pour les utilisateurs de Windows.
https://community.chocolatey.org/packages/incus/7.2.0
Paquet Winget du client Incus¶
Le client Incus est aussi disponible sur Winget pour les utilisateurs de Windows.
https://winstall.app/apps/LinuxContainers.Incus
Support¶
Les versions de fonctionnalité d’Incus ne sont supportées que jusqu’à la sortie de la suivante. Les personnes souhaitant un support plus long et des changements moins fréquents devraient plutôt envisager d’utiliser Incus 7.0 LTS.
Le support communautaire est disponible sur : https://discuss.linuxcontainers.org
Un support commercial est disponible sur : https://zabbly.com/incus
Les bugs peuvent être signalés sur : https://github.com/lxc/incus/issues
Anciennes nouvelles¶
- 30 mai 2026
- 5 mai 2026
- 27 mars 2026
- 27 févr. 2026
- 23 janv. 2026
- 19 déc. 2025
- 29 nov. 2025
- 31 oct. 2025
- 26 sept. 2025
- 29 août 2025
- 15 août 2025
- 1 août 2025
- 28 juin 2025
- 30 mai 2025
- 25 avr. 2025
- 4 avr. 2025
- 28 mars 2025
- 28 févr. 2025
- 24 janv. 2025
- 19 déc. 2024
- 13 déc. 2024
- 15 nov. 2024
- 3 oct. 2024
- 17 sept. 2024
- 6 sept. 2024
- 9 août 2024
- 12 juil. 2024
- 28 juin 2024
- 31 mai 2024
- 7 mai 2024
- 4 avr. 2024
- 26 mars 2024
- 23 févr. 2024
- 29 janv. 2024
- 26 janv. 2024
- 21 déc. 2023
- 27 nov. 2023
- 28 oct. 2023
- 7 oct. 2023



