XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    • Profile
    • Following 0
    • Followers 1
    • Topics 18
    • Posts 435
    • Groups 0
    J Offline
    1. Home
    2. john.c

    john.c

    @john.c

    137
    Reputation
    119
    Profile views
    435
    Posts
    1
    Followers
    0
    Following
    Joined
    Last Online
    Location United Kingdom

    john.c Unfollow Follow
    • RE: WORM Backups with XCP-ng / Xen Orchestra - Seeking Solutions & Experience

      @SylvainB said in WORM Backups with XCP-ng / Xen Orchestra - Seeking Solutions & Experience:

      Hello everyone,

      I'm exploring options for implementing WORM (Write Once, Read Many) capabilities for my backups within my XCP-ng environment, specifically using Xen Orchestra.

      My current setup:

      • XCP-ng Version: 8.3
      • Xen Orchestra Version: 5.106.4 (Stable)
      • Intended Backup Target: Synology NAS

      My primary goal is to ensure that my backup data, once written, becomes immutable for a defined retention period, offering protection against accidental deletion or ransomware attacks.

      My questions are:

      1. Does Xen Orchestra offer any native WORM features or integrations that I might be overlooking for its backup jobs?
      2. If not directly, has anyone successfully implemented WORM backups with a similar perimeter (XCP-ng, Xen Orchestra, and potentially a Synology NAS or other storage solution)? I'm very interested in learning about your setup, the specific technologies you used (e.g., storage features, specific configurations), and any lessons learned or best practices.

      Any insights, architectural recommendations, or shared experiences would be highly valuable.

      Thank you in advance for your help!

      Best regards,

      SylvainB

      You can setup in the Synology its WriteOnce feature, then configure the appropriate configuration settings, including retention ones.

      This will prepare the appropriate WORM environment you’re looking for. It will work well due it being the equivalent to Vates solution and/or the S3 based one.

      https://kb.synology.com/en-in/search?tags[]=WriteOnce

      posted in Backup
      J
      john.c
    • Vates

      @olivierlambert Hi Vates Team,

      I’m a member of the tech community in East Anglia (UK), and I recently proposed Vates as a speaker for our upcoming regional developer conference, nor(DEV):con 2027 (taking place 24th–26th February in Norwich).

      The proposal generated immediate interest on the official event Discord, with the organizing committee explicitly reaching out to note that "more sponsors are always welcome."

      Sponsorship packages at nor(DEV):con include prominent exhibition spaces at the King's Centre venue and guaranteed 30-minute speaking slots (which can be commercial/product-focused, unlike the strictly technical CFP tracks). Given your work with XCP-ng and Xen Orchestra, it would be an incredible fit for the region's infrastructure, DevOps, and backend engineering audience.

      You can check out the sponsorship tiers directly at https://nordevcon.com/sponsor or submit a talk via their Sessionize CFP at https://sessionize.com/nordevcon-2027/.

      Would love to see Vates represented here!

      posted in Vates events vates open source conferences development
      J
      john.c
    • RE: Broadcom removed public access to VDDK download links

      @afk said:

      Hi everyone,

      Some of you may already be aware of this but I learned the news this morning.

      https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/

      Essentially, Broadcom has decided, without any announcement, to remove all download links (and even some documentation it seems) for VDDK.
      This impacts all migration tools that use the VDDK for copying data of VM disks.

      If you have any version of VDDK, please keep it somewhere safe and make backups.

      I only have a x86-64 linux release from september 2025 that I used for testing V2V. Obviously, I can't share any link here but the release has the following sha256 hash:

      79d215198f1b8fd1d240a16b27ac2543c521ae2afdc1876444c2acf8945d74ca VMware-vix-disklib-9.0.0.0.24742305.x86_64.tar.gz

      Apparently, web archival links are also taken down.

      @olivierlambert
      With Broadcom removing public access to VDDK downloads, we now have users who either cannot obtain VDDK at all or whose existing VDDK installations (main + backup) have become corrupted.

      This creates a real need for a fully open‑source fallback path inside V2V, one that still meets the performance requirements normally associated with VDDK.

      The open‑source community has already demonstrated that VDDK‑level throughput is achievable without VMware’s proprietary stack. Several projects have shown that:

      • Parallel NBD can saturate modern storage bandwidth when implemented correctly
      • Highly multithreaded block pipelines can outperform single‑threaded VDDK transfers
      • A throwaway Linux Proxy Copy VM can act as an efficient intermediary, reading blocks via NBD and streaming them directly to the destination hypervisor.

      This approach avoids VDDK entirely, remains fully open source, and provides a reliable fallback for users who can no longer access VMware’s proprietary components.

      Given the direction Broadcom is taking, having this fallback inside V2V would significantly improve resilience for XCP‑ng users and ensure long‑term independence from VMware licensing changes.

      The Proxy Copy VM must be treated as an ephemeral orchestration component — automatically excluded from the migration set and destroyed once the transfer completes — ensuring it never interferes with HA, LB, or startup/shutdown sequencing.

      This architecture also gives Vates a clean, open‑source answer to Broadcom’s decision to pull public VDDK access — ensuring V2V remains fully functional even if VMware continues removing or restricting proprietary components.

      posted in Migrate to XCP-ng
      J
      john.c
    • RE: Hosts compatibility

      @wtdrisco said in Hosts compatibility:

      As I am starting to build an environment for testing to replace VMWare, I had a question related to hardware.

      When setting up multiple hosts, do these need to match the same specs (like VMWare?) for HA (moving VMs from host to host)?

      I have several DELL R series servers, and some do not have the exact same CPU model or one has less memory than the other.

      When setting up (HOST POOLS??) if I needed to migrate VMs, will this support different host configurations?

      If the the hosts don't match by close enough, especially if their capabilities (e.g. instruction sets) and specifications. Then in the case of capabilities then the non-matching ones will be suppressed by XCP-ng so that they all match. Also when migrating the specifications, of hosts really need to match so that when VMs are placed on the hosts. There's no issues when live migrating between the each of the pool member hosts.

      As the VMs expect at least a certain number of cores dependent on the hosts, and the number specified per each VM. If this number isn't met then that VM can't migrate to a specific host, which don't meet or exceed it.

      posted in Hardware
      J
      john.c
    • RE: XCP-ng 8.3 betas and RCs feedback 🚀

      @ThierryC01 said in XCP-ng 8.3 betas and RCs feedback 🚀:

      @bleader Update successful, no issue so far. There is just a message appearing when starting the update: "Delta RPMs disabled because /usr/bin/applydeltarpm not installed."

      All VM working for now.

      That's harmless. It's just notifying that the system doesn't have deltarpm package installed. This package reduces the size of updates based on what's already installed.

      posted in News
      J
      john.c
    • RE: First SMAPIv3 driver is available in preview

      @still_at_work said in First SMAPIv3 driver is available in preview:

      Hello @olivierlambert ,

      I am joining this topic as I have a few questions about SMAPIv3:

      • Will it allow provisioning of VDIs larger than 2TB?

      • Will it enable thin provisioning on iSCSI SRs?

      Currently, the blockers I encounter are related to my iSCSI storage. This is a major differentiating factor compared to other vendors, and resolving these blockers would significantly increase your market share.

      Thanks !

      @still_at_work The size limit of the VDI is due to the file format used for these, which is VHD (https://en.wikipedia.org/wiki/VHD_(file_format)). This format can't support more than 2TB, it's known about and are dealing with the issue. It will likely result in a change or addition of a new VDI format likely to be qcow2 unless necessary software for VHDX format is fully open sourced and software for Xen is created which enables create, read, write and use of this format.

      It's not a limitation of iSCSI as it also emerges with both NFS and SMB based connections.

      posted in Development
      J
      john.c
    • RE: Tips on installing XO

      @jasonnix The Linux distribution operating system restricts certain commands, operations and/or path (location) to the root account, as well as the location owner.

      The path your trying to write to is just one such location as the location is read only to non-root users. If you really wish to write to /usr/local/src then root account is required.

      If you use the root account to install then the directory and the Xen Orchestra files will be owner by root. You would need to create a non-root user for the xen orchestra server process. As well as change ownership of the Xen Orchestra files and folders to that non-root account. Though at least the ones which Xen Orchestra should be able to modify as required, when needed.

      As well as provide the necessary sudo permissions for the necessary commands to that account.

      Using root account to run exposes any vulnerabilities present to the capacity of being exploited as root (aka Administrator) privileges.

      Also how good is your internet connection and your connection to GitHub? Cause you could be experiencing a time out packet loss connection issue.

      posted in Xen Orchestra
      J
      john.c
    • RE: 🛰️ XO 6: dedicated thread for all your feedback!

      @Octopuss said in 🛰️ XO 6: dedicated thread for all your feedback!:

      @olivierlambert Well ok, it's just that last time I tried to ask about stuff I was politely told off because I used the installation script instead of paying (that's not the literal formulation but it's basically what the person responding meant).

      I know nothing about any blogs, I just check the main xcp website (FFS I am not even allowed to post links, what a forum...) from time to time, so I have no idea. I just updated the admin interfce for the first time since moving over from ESXi, and was puzzled why it looked the same as the "castrated" lite version when previously (which means v5, apparently) it was full of features. I had no idea it wasn't a completed product.

      TL;DR: I am just an idiot who installed this few months ago and has no idea about the details. shrug

      You were told off if the script was 3rd party because officially, the scripts may have made changes to the Xen Orchestra source code prior to compilation. They have a set of steps, for building from source which are able to receive support in the forums for. Anyway getting paid support if an organisation is best as their pro support is top notch!

      With the blogs which are being referred to are under the “News” links. Which detail releases and other news worthy information.

      You can post links but it does take some work, also make sure you’ve read the rules, also going through the introduction training which a forum function bot runs. Doing this will eventually earn you more access and feature functionality. It’ll help you get used to the forums functions.

      The XO 6 is a minimum viable product currently, but is growing from there as features from v5 transitions to v6. If there’s features missing from v5 and v6 that are needed please enter them on the Feedback portal, so they can be voted on. It’s link is in several XOA update and release news posts (especially 6.0 and 6.1).

      Read both these posts along with others along the way, it will help you get caught up on all of the Xen Orchestra releases and updates.

      posted in Xen Orchestra
      J
      john.c
    • RE: [PACKER] soucis avec cd_files

      @olivierlambert said:

      @john.c I really liked your "Jean C." signature before your edit 😎 You should keep it 😄

      I learned a bit of French in 6th form college many years ago now, as part of learning your culture. As part of a Skillpower course unit assignment. As part of this course during Sept 2001 to Summer 2006 went on an academic day trip visit to Boulogne, France.

      But it was to a level that was useful for when going on holidays, so wasn’t very fluent.

      posted in French (Français)
      J
      john.c
    • RE: [PACKER] soucis avec cd_files

      @jeremie1977 said:

      Bonjour,
      Nous sommes en plein POC de Vates et je test le build de nos images RHEL avec Packer (d'ailleurs un grand merci à @bvivi57 et @ataxyanetwork pour les tutos et exemples qui m'ont fait gagner un temps précieux ^^ ).

      J'ai remarqué que le paramètre "cd_files" ne permettait pas de monter le kickstart au boot
      Le provider expose cd_files, mais le contenu n'est pas visible par l'installeur (ou n'est pas attaché à la VM...je n'ai pas sût identifier).
      J'ai même tenté avec "floppy_files"...idem.
      Est-ce normal ? Voulu ?

      Du coup, dans des environnements sans DHCP pendant l'installation, cela empêche l'utilisation d'un kickstart embarqué et oblige à mettre en place une IP via la "boot_command" avec une configuration réseau statique (ce qui oblige a multiplié les builds si plusieurs environnements/site)
      Rien de dramatique en soit mais sur les provider Packer Vmware et Nutanix que nous utilisons par ex, cd_files nous permet de couvrir les environnements isolés (air-gapped) et/ou sans DHCP et simplifie grandement les builds automatisés en rendant le code le plus idempotent possible.

      L'intérêt est multiple :
      Environnements air-gapped : aucun serveur HTTP nécessaire.
      Moins de dépendances : le build est autonome.
      Compatibilité avec les autres builders Packer (VMware, Nutanix, QEMU...), où nous utilisons cette fonctionnalité pour nos Builds
      Sécurité : le kickstart n'est pas exposé sur le réseau, même temporairement.

      Si la raison pour laquelle le fichier Kickstart ne peut pas être connecté en réseau ou autrement accessible, c'est parce qu'il contient des secrets. Cela peut valoir la peine de regarder et de vérifier le logiciel de service de détenteur sécurisé secret OpenBao (https://openbao.org/). Qui est un fork public open source de Hashicorp Vault, avant l'entrée en vigueur de la licence BUSL dans les versions ultérieures de Vault. Un autre conseil utile est de combiner l'isolation du masque de sous-réseau avec l'isolation basée sur le VLAN.

      Quoi qu'il en soit, saviez-vous qu'une instance de Cockpit, exécutant Cockpit Image Builder peut être utilisée comme Packer, pour créer des images "dorées" de VM via OSBuild ?

      Quoi qu'il en soit, bonjour et bienvenue dans la communauté Vates VMS, j'espère que vous la trouverez utile, épanouissante, accueillante et/ou amusante.

      Sincèrement,

      Jean C.

      posted in French (Français)
      J
      john.c
    • RE: Future Architecture?

      @herhin2017 said:

      @john.c
      Your absolute wright, i do my best and train about 25 young engineers per year on linux (we use debian). I also see more and more startups or small companies building their infrastructure on linux.
      Best greetings from austria

      It may be worth getting in line and noting the mention of EFI based servers for official Vates support with XCP-ng version 9.0 and above, in government reports. That way when the school’s hardware is refreshed it can be ensured that your provided with EFI capable servers, in time for XCP-ng version 8.3 EOL.

      I personally are already ready for XCP-ng version 9.0 due to my servers being Dell PowerEdge R620 for XCP-ng hosts. Along with Debian version 13.6 on the VMs. While using a Dell Precision 3590 to manage those systems.

      The “wright” makes your above now sound like a wheel wright, and its profession instead of “right” in for when correct or agreeing with someone or something.

      posted in News
      J
      john.c
    • RE: Future Architecture?

      @herhin2017 said:

      Hello John C.
      In Austria, the Government pays Microsoft Licenses for everything. So every school can use their Software (you know what i mean). To use Linux or something else is not really well received. I am not able to use corporations with 3rd party comp. and i am not allowed to take money from somewere else!

      So that may be about to change, depending on how far an on going transition in Austrian government goes. As with your country’s military now on Linux and LibreOffice your academic system is going to need to be training, Austrian children on those systems to prepare them, for if they join the military.

      https://linuxsecurity.com/news/government/linux-security-defense

      posted in News
      J
      john.c
    • RE: Future Architecture?

      @herhin2017 said:

      Yes, your wright! I know about that. As i mentioned, our machines are really working perfect (they can easily be a productive system) I am asking because our school does not have much money (in fact nothing) and i will go on with my lessons in hypervisors with xcp-ng.
      THANKS TO EVERYONE who works on this project - i like it!!
      P.S. If you need user tests in grater scale, we can do it (10 machines) and we have time.

      Welcome to the forums!

      To answer your question while expanding on @Poddingue's excellent point: it all comes down to the AlmaLinux base chosen for the dom0 control domain. While AlmaLinux 10 does offer an alternative x86_64-v2 compilation option for older processors, relying on a sub-baseline build for a modern hypervisor can limit your performance and future third-party repository support.

      To truly get the most out of XCP-ng 9.0 when it reaches stable release—and to avoid the hard limitations of the modern EFI and Secure Boot requirements—you will want to target at least generation 9 of HPE servers (Gen9) at a minimum.

      Since you are dealing with a tight school budget but need to acquire a large number of machines for your network engineering students, here are the most effective ways to source that volume:

      • Corporate Hardware Donations: Depending on your school's official legal status (such as Gemeinnützigkeit), you might be able to get these machines donated for free. Many large companies in Austria cycle out their enterprise hardware every few years and actively look to donate working Gen9 or Gen10 servers to schools for tax benefits or community goodwill. It is highly worth reaching out to local IT departments or tech companies!

      • Professionally Refurbished Bulk Batches: Sourcing former enterprise hardware in large, uniform batches is your next best path. Gen9 servers offer excellent performance for a very low price right now. Keeping the hardware identical also makes managing your pool templates significantly easier.

      • Academic Programs & Vates Discounts: If your rollout scales up and you eventually need official commercial backing, it is well worth reaching out directly to Vates. Let them know you are an educational institution; they are often very supportive of academia and may offer steep volume or academic purchasing discounts for schools.

      Good luck setting up the lab for your hypervisor lessons!

      P.S. A quick, friendly tip for your English writing: drop the "w" when you want to agree with someone. If you use "write", it sounds like the action of writing words down on paper (schreiben). To agree with someone, the correct phrases are "You're right" or "You are right" (Du hast recht / Sie haben recht).

      posted in News
      J
      john.c
    • RE: Future Architecture?

      It depends on whether the Alma Linux core chosen for dom0 is the one for v3 and v4 or the one for v2. As AlmaLinux also has a variant in vanilla not just for baseline v3 and v4 but also for one baseline below in other words v2.

      posted in News
      J
      john.c
    • RE: Pool metadata backup failed after xoa upgrade

      @poddingue said:

      There's a similar report on 6.8 in https://xcp-ng.org/forum/topic/12453, where @flakpyro said it got fixed through a support ticket and that @florent would know the exact fix.

      I read through the 6.9.0 changelog, but I couldn't find an entry about metadata backups or Body Timeout Error, so I can't confirm that moving to the latest channel fixes it, though it may have gone in without a changelog line. 🤷

      If you have a support contract, a ticket that points at that thread might be the quickest way to the patch Florent made.

      It is in the 6.9.0 change log but not where you might expect, even as a backup bug fix. In this case it’s filed under the miscellaneous (misc) section as “Fixed: BodyTimeoutError during long transfers”. Given where it is in the change log you may have missed it.

      If it isn’t in the change log then why is it in the release announcement?

      posted in Backup
      J
      john.c
    • RE: XOA Unable to connect xo server every 30s

      @GregBinSD said:

      Here are two more notes regarding the XO6 "Unable to connect to XO server. Retry" message, which pops up after 30 seconds.

      It occurs when either the Chrome or the Microsoft Edge browsers are used on my Windows 11 PC.

      However, I often use a Samsung Tab-A9 (tablet), and it does not have this issue with XO6. It uses the Chrome browser.

      To enlighten you the Microsoft Edge your talking about is not the original release (from Windows 10). It’s the Chromium based release from during Windows 10 and has been that one ever since. The original release of Microsoft Edge had its own rendering engine called MSHTML. The current modern Edge effectively shares a common upstream code base with Google Chrome, namely Chromium.

      The Samsung Tab-A9 doesn’t have the issue even though it, uses the same browser namely Google Chrome. This is the case because the tablet uses a version of Google Android, which has its own kernel, which is a fork or variation of the Linux Kernel.

      posted in Xen Orchestra
      J
      john.c
    • RE: Pool metadata backup failed after xoa upgrade

      @jacob.becker said:

      Hi!
      After the XOA update to 6.8.2 (Stable), the Backup of the pool metadata fail with

      Error: Body Timeout Error
      

      after aprox. 5 minutes.
      Other Backup Jobs run without issues.

      @jacob.becker On the latest channel for XOA updates version 6.9 (6.9.0) has a fix for Body Timeout Error issue, no sign of a fix in 6.8.0 to 6.8.2 version series. Change channel and you’ll have the fix or open for Vates staff via PM a support tunnel access so they can patch your 6.8.2 with the one specific for this version.

      This is an SERIOUSLY urgent action to fix the backup issue, but the Critical part is that it also fixes an important security vulnerability (VSA-2026-044).

      posted in Backup
      J
      john.c
    • RE: Internet connectivity - Check XOA failed.

      @acebmxer said:

      @john.c

      We currently dont use ipv6 internally. No network changes were made at this location other then moving the proxy to the correct network for nbd connections. With that move some how made the ipv6 issue appear. So it was just easy to disable ipv6 in the proxy. I guess if we ever switch to ipv6 (no plans too) then i guess i will have to look back into it.

      @acebmxer @zorro If any of your VMs are facing the public internet, completing your IPv6 Readiness compliance is vital. With regional internet registries completely exhausted of free-pool IPv4 space, modern endpoints and cloud architectures are increasingly deploying IPv6-only infrastructure.

      If you are referring to an internet access proxy, disabling IPv6 introduces significant architectural risk. If any upstream transit provider, carrier, or edge CDN in the path to your target FQDN transitions to an IPv6-only topology, your access path will break, causing a hard outage. If you are specifically utilizing a transit provider like XO Proxy, transitioning to dual-stack or IPv6-only transport is even more critical to ensure deterministic routing across the wider internet footprint.

      From an architecture and security standpoint, IPv6 introduces critical enterprise enhancements:

      • SLAAC Privacy Extensions: Enables temporary, rotating addresses to mitigate device fingerprinting and endpoint tracking.
      • Native IPSec Integration: While RFC 8200 technically shifted IPSec from a hard protocol requirement to an optional component, it remains a native architectural element of the IPv6 stack. Unlike IPv4—where IPSec must be bolted on as an awkward overlay—IPv6 accommodates encryption headers natively, simplifying the deployment of secure end-to-end transport encryption across enterprise and government domains.

      If you need to pitch this network-wide transition to leadership for project approval, I highly recommend framing it around business continuity and risk mitigation. Pointing out the looming vulnerability of upstream IPv6-only transit paths—combined with the compliance advantages of native architectural security—should give you the exact leverage needed to get this budgeted, planned, and implemented.

      posted in Management
      J
      john.c
    • RE: Internet connectivity - Check XOA failed.

      @acebmxer said:

      @poddingue

      I had issue with a remote proxy.. showed error in xoa untill i disabled ipv6. But only with one of two remote proxies. This was in a support ticket.

      Did you test your full stack IP v6 readiness with one of the online testers? The reason being your local LAN maybe ready even at your router level, but if your ISP doesn’t have full stack (or even dual full stack - v4 and v6) then FQDN addresses which are only on IP v6 only may not work). Also v4 and v6 IP address has to also be associated with the FQDN being contacted.

      posted in Management
      J
      john.c
    • RE: HA causes reboot of xcp-ng nodes

      @tjkreidl said:

      @john.c Keeping the various network traffic isolated according to specific usage (management, storage, VMs, etc.) is always a good idea. The last system I managed had 10GiB LACP bonds and using VLANs to isolate traffic and that worked fine with a four-node pool running around 80 or so XenDesktop instances per node. Never experienced any congestion issues. Each dom0 had a ton of memory and I believe it was either 8 or 16 VCPUs to make sure there were sufficient compute and memory allocations to allow for sometimes very heavy loads. It also helped that I eventually added GPUs to take on some of the computational load, in particular when some of the VMs were running applications employing heavy graphics.

      @tjkreidl Thanks Tobias, that’s great validation! Running 10GiB LACP bonds with proper VLAN isolation is definitely the ultimate goal for production stability, especially when pushing 80+ VMs per node.

      Your point about dom0 resource allocation is also huge—people often forget that saturated vCPUs and starved dom0 memory can bottleneck network processing just as fast as a saturated physical link under heavy loads. Giving dom0 the extra compute headroom ensures the orchestration layer doesn't drop packets when backups or migrations scale up across that many instances.

      posted in Management
      J
      john.c