Subcategories

  • VMs, hosts, pools, networks and all other usual management tasks.

    483 Topics
    4k Posts
    olivierlambertO
    Hi! It is not the XOCE to xo-server link, it is the credential xo-server uses to log into XAPI on your host. It has to be reversible, not hashed, because xo-server replays it to XAPI on every connect and auto-reconnect. So yes, plaintext by default is expected. The security perimeter here is Redis itself (bound to localhost or a unix socket, never exposed) and root access on the XO VM. That said, since XO 6.5 there is an opt-in encryption at rest. In your xo-server config: [redis] encryptCredentialDatabase = true On the next start, every record is encrypted with AES-256-GCM (values get an enc: prefix) and index keys become HMAC-SHA256 blind indexes, so hostnames and emails are not readable either. The key is split in two halves, one in XenStore (vm-data/xo-encryption-key) and one in /var/lib/xo-server/data/xo-encryption-key. Caveats for a source install: XO must run as a VM on XCP-ng/XenServer with xen-tools, and xo-server needs access to the xenstored socket (root, typically). Config export then requires a passphrase. If you lose one key half while encryption is on, do not restart: XO would regenerate both halves and the existing records would become undecryptable. Full doc: https://docs.xen-orchestra.com/credential-encryption About the PoolAlreadyConnected part, that is a separate issue. It means two server entries resolve to the same pool, typically a slave host registered next to the master, or the pool re-added after a master change. Removing the entry with DEL xo:server:<id> is not the right fix: it drops the hash but leaves the id in xo:server_ids and in the host index. Remove the server from the UI instead. If the error persists, it is the other entry pointing to that same pool that needs to go.
  • ACLs, Self-service, Cloud-init, Load balancing...

    106 Topics
    869 Posts
    T
    @mpiton Thanks for looking into this, I guess it wasn't apparent that I needed to click the Save Configuration button for that plugin. I did that and confirmed that the secret now survives an xo-server restart. Thanks again!
  • All XO backup features: full and incremental, replication, mirrors...

    527 Topics
    6k Posts
    J
    @christopher-petzel Ok! Thanks!
  • Everything related to Xen Orchestra's REST API

    87 Topics
    650 Posts
    A
    @poddingue Borrow away - "smoke alarm" is a better name for it than anything we had, so we might borrow it right back. Since you mentioned reading the matrix - here is the classification you would be reading, straight from the file: grep access: dadl/xen-orchestra.dadl | sort | uniq -c 49 access: admin 21 access: dangerous 122 access: read 75 access: write 122 of the 267 tools are plain read - that is the entire surface a review-capped agent gets. The other 145 exist in the same file, but for that agent they might as well not. The whole security taxonomy is greppable plaintext - which is rather the point of a declarative format. And if anything in the matrix looks wrong or missing, this thread is exactly the right place - real-world corrections are how it improves.
  • Terraform, Packer or any tool to do IaC

    51 Topics
    484 Posts
    K
    @Cyrille We can't disable the embedded CCM. Disabling the embedded CCM in RKE2 impacts core cluster bootstrap behavior because it is a bootstrap-critical component responsible for core node lifecycle management.
  • VDIS not showing in XO5, but are in XO6 and on the VM itself ?

    4
    2
    0 Votes
    4 Posts
    667 Views
    P
    @kent you would have to rollback to early december 2025 XO/XOA (before the 10 of december) quite a long way I'm just waiting the devs to eventually fix it as we have other way to manage VDIs (API calls)
  • XOA SocketError: Other side Closed

    1
    0 Votes
    1 Posts
    212 Views
    No one has replied
  • XOA Create VM and Delete VM Struggling..... Tasks Getting Stuck.....?

    15
    0 Votes
    15 Posts
    2k Views
    G
    @MichaelCropper Truenas on bare metal just as storage, XCP-NG is also bare metal on 3 hosts to make a pool. That's the minimum if you want to enable High Availability, it also works really well as a "normal" pool which is what I have. Rolling Pool functions are great, click the button and the system moves the VMS off of the host that need updates, reboots, moves VMs off of the next host, repeat. Only works with Shared storage.
  • Second IP for Hosts Interface

    2
    0 Votes
    2 Posts
    393 Views
    P
    @jqueiroz said in Second IP for Hosts Interface: I have a situation where I would like to add a second IPv4 address to the management interface of a host. I am installing a host that will be used in another location and I would like to add the address of that location to the management interface before shipping the machine there. Is it possible to do this, or should I continue using the current procedure (making the necessary configurations and change the address shortly before shutting down the machine and packing it for transport)? there is a nuance between secondary IP and secondary MANAGEMENT IP if you have multiple NICS, you could add & configure the destination site IP on it, but it is not flagged management yet. once the server gets on the new site, you could access web ui by this IP address (or SSH) and then either go to web console/xs server or SSH and do the necessary to change management to the good PIF/IP ?
  • Backup fails only on master with VM_NO_SUSPEND_SR

    23
    0 Votes
    23 Posts
    5k Views
    G
    An intake is created for review with XO team. Thanks for the feedback @puffymob !
  • Rolling Updates Failed

    4
    0 Votes
    4 Posts
    811 Views
    J
    Hi! ISO-SR over HBA/FC would be very nice, especially when migration form a SAN vmware-System to XCP-NG. One other thing is altering. Errors like "VM cannot be migrated" or similar should not be silent but should be very visible / even mailed to the admin. Another thing (could be cosmetical though) in my opinion is that a failed Rolling upgrade remains visible with a half fulled progress bar in the task-view. this is confusing.
  • VM metadata import fail & stuck

    9
    0 Votes
    9 Posts
    1k Views
    nikadeN
    @henri9813 Ahh alright, I understand now! Thanks for clarifying.
  • V5 works fine with XenServer 8.4, v6 doesnt work?

    12
    3
    0 Votes
    12 Posts
    2k Views
    E
    @MathieuRA As announced, I have now installed branch xo6/update-site-dashboard and it seems to be working. It no longer loads endlessly and shows me that I haven't configured anything yet Thank you very much!
  • XO Backup [NOBAK] for full backups

    Solved
    43
    0 Votes
    43 Posts
    25k Views
    florentF
    @dave.opc that's it keep us updated on this
  • 0 Votes
    2 Posts
    369 Views
    olivierlambertO
    Hi, Thanks for your feedback! Let me ping @bastien-nollet or @pdonias maybe
  • Large VM Migration fails, host has free disk - Storage_error

    6
    0 Votes
    6 Posts
    1k Views
    ditzy-oliveD
    I managed to do the migration by splitting over the two storages the remove system has. This made it work and I managed to move that one VM. However I still have a second one It's thick provisioned (LVM - never can remember the terms thin/thick). Offline isn't an option unfortunately since I need the services running, can't take if off for 15 hours. But since two of the services are docker containers, both having a separate disk of 500GB, I can make it work by setting up a two new systems and moving everything from the container there. Which would reduce the size by 1TB and make thing easier to manage. Was hoping I could finally upgrade the main xcp-ng last weekend.
  • Changing XOA Registration Email (again)

    2
    0 Votes
    2 Posts
    423 Views
    olivierlambertO
    Hi, Have you followed https://help.vates.tech/kb/en-us/8-technical-support/15-open-a-support-ticket ?
  • Changing XOA Registration Email

    2
    0 Votes
    2 Posts
    450 Views
    DanpD
    @tsukraw Your best option is to open a support ticket so that we can assist you on updating the XOA registration.
  • Xen Orchestra Node 24 compatibility

    9
    0 Votes
    9 Posts
    2k Views
    olivierlambertO
    Nice find! Is there's any plan for Debian to backport that patch?
  • Yarn gpg key expired/ xo bfs on debian 12

    Moved
    1
    0 Votes
    1 Posts
    669 Views
    No one has replied
  • Kubernetes Recipe VM failed to start - Raise Network Interfaces

    12
    1
    0 Votes
    12 Posts
    3k Views
    CyrilleC
    Hi @jacob.becker, We identified the issue last weekend, and we're currently working on a solution. We plan to include a fix in the next XO release.
  • XO 6 backup job missing VM info on failure.

    1
    2
    0 Votes
    1 Posts
    218 Views
    No one has replied
  • Orphan VDIs in XO show health problem

    15
    4
    0 Votes
    15 Posts
    2k Views
    W
    @Pilow Does disk show up after you do the snapshot? If it is able to do the snapshot there is a high chance it can boot up. So try booting up (and check for disk) and shut it down and do the snapshot at that time if the disk show up. It helps to boot up on the old v5 commit and check from that side too if you have both copy before the commit update. Yep I can confirm that snapshot doesn't always work. But using the older v5 that used to work before the update does get it showing up on the newer v5 commit if I go through whole snapshot, revert, etc. one of those case work.
  • 0 Votes
    7 Posts
    2k Views
    olivierlambertO
    We are not energy efficiency experts, while EasyVirt people are. I think they already have some stuff and it might be just a matter of plumbing.
  • ISO won't show since XO6 Default

    5
    2
    0 Votes
    5 Posts
    844 Views
    MathieuRAM
    Hi @Kptainflintt, I don't think this is related to XO6, but probably to this PR: https://github.com/vatesfr/xen-orchestra/pull/9231 VDIs with snapshot_of: <something> are now recognized as snapshots