Reference
Scope
Look-up facts for OpenNebula 7.x: releases and support windows, editions, certified platforms, services, ports, drivers, configuration keys, VM states, access-control vocabulary, published benchmarks, and a hardening checklist. Figures are from the official 7.2/7.4 release notes and docs unless noted. For how the pieces fit together see Explanation; for tasks see How-to Guides.
Release History
| Version |
Codename |
Date |
Notes |
| 7.4.1 |
Helix |
2026-09-10 |
Maintenance release (fixes, e.g. live storage migration with NVRAM VMs) |
| 7.4.0 |
Helix |
2026-07-27 |
Redesigned Sunstone; OneKS and LVM SAN storage move to Community Edition; NVIDIA NICo bare metal (EE); OneBEX backup exporter; Ubuntu 26.04 |
| 7.2.1 |
Dark Horse |
2026-05-21 |
EE maintenance release; OneKS first shipped to EE customers |
| 7.2.0 |
Dark Horse |
2026-04-07 |
gRPC API, NVIDIA Fabric Manager (EE), storage live migration, Pure Storage FlashArray driver, OneForm, memory encryption, Sunstone 2FA enforcement |
| 7.0.0 |
Phoenix |
2025-07 |
New scheduler framework + OneDRS; Ruby Sunstone, vCenter, ebtables and legacy hybrid drivers removed |
| 6.10.x |
Bubble |
2024 (6.10.5: 2025-11) |
FireEdge Sunstone default; OneDeploy; OneSwap; Firecracker, LXD, Docker Machine removed |
Date sources
7.2.0/7.2.1 dates come from the OpenNebula Release Schedule wiki as surfaced in search results; 7.4.0 (2026-07-27) and 7.4.1 (2026-09-10) come from release announcements and match the publish dates of the opennebula Ruby gem on rubygems.org (7.4.0 on 2026-07-27, 7.4.1 on 2026-09-09). 7.0.0 was published on rubygems.org on 2025-07-03.
Release Policy and Support Windows
| Item |
Value |
| Minor (feature) release cadence |
About every 6 months (7.0 Jul 2025, 7.2 Apr 2026, 7.4 Jul 2026) |
| Pre-releases |
Beta builds versioned x.(y-1).80/.85 (e.g. gem 7.3.80.pre, 7.3.85.pre before 7.4) |
| STS support (EE) |
9 months (6 months until the next release + 3 months) |
| LTS support (EE) |
At least 36 months; LTS every ~2 years; Extended Life add-on up to 4.5 years |
| CE maintenance |
Community Forum support; maintenance (x.y.z) packages are primarily an EE benefit |
| Which 7.x lines are LTS |
TBD — not confirmed in sources reachable on 2026-09-25; check the Release Policy wiki |
Source: Release Policy wiki, What is OpenNebula EE.
Editions
|
Community Edition (CE) |
Enterprise Edition (EE) |
| License |
Apache License 2.0 |
Packages distributed under commercial terms to customers with an active subscription |
| Access |
Public repos at downloads.opennebula.io/repo/<version>/... |
Enterprise repos + Customer Portal |
| Maintenance releases |
Limited; upgrade to next minor |
Every ~3 months, STS/LTS lifecycle |
| Migration tools |
opennebula-migration (onedb, onecfg) included since 7.0 |
Included |
| EE-only features (7.2/7.4) |
— |
NVIDIA Fabric Manager integration, NVIDIA NICo Bare Metal as a Service, Veeam integration, NetApp driver; new LVM subsystem was EE in 7.2 |
| Moved EE to CE |
Restic backups + Prometheus monitoring (6.10); LVM SAN storage + OneKS (7.4) |
— |
EE feature list changes each release
The EE-only set moves every release (features graduate to CE). Check the "(EE)" markers in the current What's New page before assuming a feature is in CE.
Subscription Pricing
| Item |
Value |
| Tiers |
Elemental, Standard, Premium (support hours 9x5 vs 24x7 differ by tier) |
| Pricing model |
Base annual fee plus a per-managed-node fee; every managed host needs a subscription at the same level |
| Published figures |
A third-party listing (SpotSaaS, 2026) reports Standard at about USD 8,750/yr + ~USD 875 per node and Premium at about USD 13,750/yr + ~USD 1,375 per node. Unverified against the official page, which blocked automated access |
Official page: OpenNebula Subscription Plans.
| Component |
Front-end |
KVM nodes |
LXC nodes |
| RHEL |
9, 10 |
9, 10 |
— |
| AlmaLinux |
9, 10 |
9, 10 |
9, 10 |
| Rocky Linux |
9, 10 (via Red Hat packages) |
9, 10 |
9, 10 |
| Ubuntu Server |
24.04, 26.04 |
24.04, 26.04 |
24.04, 26.04 |
| Debian |
12, 13 |
12, 13 |
12, 13 |
| SUSE Linux Enterprise |
15 |
15 |
— |
| openSUSE |
16 |
16 |
— |
| Database |
SQLite (default) or MariaDB/MySQL from the distro |
— |
— |
Change from 7.2
7.2 certified Ubuntu 22.04 and 24.04; 7.4 moves to 24.04 and 26.04 and adds Rocky Linux. 7.4 also requires that hypervisors in the same Cluster (and all HA Front-ends) run the same OS distribution and version.
Certified Infrastructure Components (7.4)
| Area |
Component |
Certified version / models |
| Storage |
Ceph |
Reef 18.2.x, Squid 19.2.x |
| Storage |
NetApp ONTAP |
9.16.1P1 |
| Storage |
Pure Storage FlashArray (docs call it "Everpure") |
Purity 6.7.2 |
| Storage |
NFS |
v4.2 |
| Networking |
802.1Q, Open vSwitch, iproute2 (VXLAN) |
Distro versions |
| Networking |
NVIDIA Spectrum-X, InfiniBand |
Supported |
| GPUs (NVIDIA) |
Ampere / Ada / Hopper / Blackwell |
A10-A100; L4, L40, L40S; H100, H200, GH200; B200, B300, GB200, GB300 |
| DPUs |
NVIDIA BlueField |
2, 3 |
| AI accelerators |
Axelera Metis |
Server 150p, Edge 130p, embedded modules |
| Monitoring |
Prometheus |
2.53.1 |
| Backup |
Restic |
0.17.3 |
| Backup |
Veeam B&R |
>= 13.0 (7.2 certified 12.3.1) |
| Billing |
WHMCS |
8.13.1 |
| Kubernetes (OneKS) |
Kubernetes |
1.34.2, 1.33.7 |
Certified scale: a single oned instance is stress-tested with 500 hypervisors without degradation; that is the maximum recommended size before federating. Some users run on the order of 2,000 hypervisors per instance, and the key-features page cites over 2,500 nodes in production (both depend on storage, networking and monitoring configuration).
Removed and Legacy Components
| Component |
Status |
Since |
Replacement |
| Firecracker driver |
Removed |
6.10 |
KVM |
| LXD driver |
Removed |
6.10 |
LXC |
| Docker Machine, DockerHub marketplace, Docker Registry |
Removed |
6.10 |
OneKE / OneKS |
| TurnkeyLinux marketplace |
Removed |
6.10 |
LXC marketplace |
| PostgreSQL backend (tech preview) |
Removed |
6.10 |
MySQL/MariaDB |
| Ruby Sunstone |
Removed |
7.0 (legacy in 6.10) |
FireEdge-based Sunstone |
| vCenter drivers |
Removed |
7.0 (legacy in 6.10) |
OneSwap migration to KVM |
| ebtables network driver |
Removed |
7.0 |
VLAN-based drivers |
| Legacy hybrid drivers (ec2, azure, opennebula) |
Removed |
7.0 |
OneForm cluster provisioning |
| Import of "wild" VMs |
Removed |
7.0 |
— |
mm_sched scheduler daemon |
Replaced |
7.0 |
one_sched driver framework (rank + OneDRS) |
Front-end Packages and Services
| Package |
Purpose |
opennebula |
oned, scheduler, monitor, core drivers |
opennebula-tools |
CLI |
opennebula-fireedge |
Sunstone web UI server (FireEdge) |
opennebula-gate |
OneGate (VM to OpenNebula API) |
opennebula-flow |
OneFlow multi-VM services |
opennebula-ks |
OneKS Kubernetes service (7.4) |
opennebula-migration |
onedb / onecfg upgrade tools |
opennebula-node-kvm / opennebula-node-lxc |
Hypervisor node setup |
opennebula-prometheus, opennebula-prometheus-kvm |
Prometheus + Grafana integration and exporters |
opennebula-swap |
OneSwap VMware-to-KVM migration |
opennebula-guacd |
Guacamole proxy for remote consoles |
| systemd service |
Role |
opennebula |
oned daemon, XML-RPC/gRPC endpoint |
opennebula-hem |
Hook Execution Manager (starts with opennebula) |
opennebula-fireedge |
Sunstone GUI server |
opennebula-gate, opennebula-flow |
OneGate, OneFlow |
opennebula-form |
OneForm cluster provisioning |
opennebula-ks |
OneKS |
opennebula-ssh-agent |
Dedicated SSH agent for oned (no key copying to hosts) |
opennebula-showback |
Periodic showback recalculation |
opennebula-prometheus |
Bundled Prometheus |
Network Ports
| Port |
Service |
| 22 |
SSH (front-end to hosts; drivers run over SSH) |
| 2474 |
OneFlow |
| 2616 |
FireEdge / Sunstone (http://<frontend>:2616/fireedge/sunstone) |
| 2633 |
oned XML-RPC API (/RPC2) |
| 2634 |
oned gRPC API (7.2+, GRPC_PORT) |
| 2101 |
oned ZeroMQ event publisher (hooks, OneKS subscriber) |
| 4124 |
Monitoring daemon (TCP/UDP) |
| 5030 |
OneGate |
| 10780 |
OneKS API (default bind 127.0.0.1) |
| 29876 |
noVNC proxy |
| 5900+ |
VNC on hypervisor hosts (VNC_PORTS) |
Drivers
| Subsystem |
Drivers (7.x) |
| Virtualization (VMM) |
kvm (QEMU/KVM via libvirt), lxc |
Datastore drivers (-d list: image, file, backup) |
fs, ceph, lvm, dev, iscsi_libvirt, restic, rsync, netapp, purefa, virtiofs, interactive (7.4 OneBEX), dummy |
System DS / transfer (-s list) |
shared, ssh, local, qcow2, ceph, lvm, fs_lvm, fs_lvm_ssh, netapp, purefa, dummy |
| Networking (VN_MAD) |
Linux bridge, 802.1Q, VXLAN, Open vSwitch (incl. SR-IOV switchdev in 7.4), plus Spectrum-X and InfiniBand integrations |
| Authentication |
core (user/password + tokens), ssh, x509, ldap, saml (7.0.1+), server_cipher, server_x509 |
| Backup |
Restic (incl. S3 backend in 7.4), rsync, Veeam (EE), OneBEX interactive export (7.4) |
The datastore/transfer lists above come from the default DATASTORE_MAD line in the 7.4 known-issues page.
Key File Locations
| Path |
Purpose |
/etc/one/oned.conf |
Core daemon config (drivers, SCHED_MAD, GRPC_PORT, ONEGATE_ENDPOINT, MAC_GLOBAL_SPACE) |
/etc/one/schedulers/one_drs.conf |
OneDRS defaults (overridable per Cluster via ONE_DRS) |
/etc/one/fireedge-server.conf |
FireEdge / Sunstone server config |
/etc/one/oneflow-server.conf |
OneFlow config (:one_xmlrpc endpoint) |
/etc/one/onegate-server.conf |
OneGate config (:server Sinatra section in 7.4) |
/etc/one/oneks-server.conf |
OneKS config |
/etc/one/vmm_exec/vmm_exec_kvm.conf |
KVM driver defaults (e.g. disk cache mode) |
/var/lib/one/.one/one_auth |
oneadmin credentials (initial password on first start) |
/var/lib/one/datastores/<id>/ |
Datastore directories on front-end and hosts |
/var/lib/one/remotes/ |
Driver scripts synced to hosts (onehost sync) |
/var/lib/one/vhost-sockets |
DPDK vhost-user sockets (7.2+) |
/var/log/one/oned.log |
Core daemon log (appended, not truncated, since 7.4) |
Configuration Keys
| Key |
Where |
Meaning |
SCHED_MAD = [ EXECUTABLE = "one_sched", ARGUMENTS = "-t 15 -p rank -o one_drs" ] |
oned.conf |
-t threads, -p placement scheduler (rank or one_drs), -o optimizer (one_drs) |
SCHED_MAX_WND_TIME, SCHED_RETRY_TIME |
oned.conf |
Scheduling-window length and retry interval |
MAX_ACTIONS_PER_HOST, MAX_ACTIONS_PER_CLUSTER, ACTION_TIMEOUT, LIVE_RESCHEDS |
oned.conf |
Scheduler action throttles and live vs cold reschedule |
GRPC_PORT = 2634, GRPC_LISTEN_ADDRESS |
oned.conf |
gRPC server (enabled by default in 7.2+) |
ENDPOINT_GRPC |
Zone / HA server |
Required for gRPC clients in HA or federation |
ONEAPI_PROTOCOL=grpc, ONE_GRPC=<ip>:<port>, --grpc |
CLI env/flag |
Switch CLI to gRPC |
ONE_DRS = [ AUTOMATION, POLICY, *_WEIGHT ] |
Cluster template |
OneDRS: manual/partial/full; pack/balance; metric weights |
ONEDRS_BLOCKED = "YES" |
VM user template |
Exclude a VM from OneDRS migrations (7.4) |
PRIORITIZE_STORAGE_MIGRATIONS |
OneDRS config |
Prefer datastore over host migrations (7.4) |
SCHED_REQUIREMENTS, SCHED_RANK, SCHED_DS_REQUIREMENTS |
VM template |
Placement filters and ranking |
MIGRATE_AUTO_CONVERGE, MIGRATE_COMPRESSED |
VM template FEATURES |
Per-VM live-migration tuning (7.4) |
BACKUP_CONFIG/DISK_IDS |
VM template |
Back up selected disks only (7.4) |
LXC_UNPRIVILEGED = "no" |
VM template |
Run a privileged LXC container (default is unprivileged) |
VM States
| State |
Meaning |
Typical trigger |
PENDING |
Waiting for the scheduler |
onetemplate instantiate, onevm release |
HOLD |
Not schedulable until released |
onevm hold, instantiate --hold |
ACTIVE/PROLOG |
Transferring disks to the host |
Scheduler deploy |
ACTIVE/BOOT |
Hypervisor starting the guest |
After PROLOG, or on resume |
ACTIVE/RUNNING |
Running |
Boot complete |
ACTIVE/MIGRATE |
Live or cold migration in progress |
onevm migrate [--live], OneDRS |
ACTIVE/SAVE_* |
Saving memory state |
onevm suspend, onevm stop |
SUSPENDED |
Memory saved on the host |
onevm suspend |
STOPPED |
Saved and disks moved back to system DS |
onevm stop |
POWEROFF |
Guest off, disks stay on host |
onevm poweroff |
UNDEPLOYED |
Off, disks moved back to system DS, host freed |
onevm undeploy |
ACTIVE/SHUTDOWN then EPILOG |
Guest shutting down, then cleanup |
onevm terminate |
DONE |
Finished (kept in DB history) |
Terminate completes |
FAILURE / UNKNOWN |
Driver error / host unreachable |
Boot, transfer, or monitoring failure |
Access-Control Vocabulary
| ACL rule part |
Values |
| Rule syntax |
<user or @group or *> <RESOURCE[+RESOURCE]>/<#id, @group or *> <RIGHTS> (e.g. @105 VM+NET/@100 USE+MANAGE) |
| Rights |
USE, MANAGE, ADMIN, CREATE |
| Resources |
VM, HOST, NET, IMAGE, USER, TEMPLATE, GROUP, DATASTORE, CLUSTER, DOCUMENT, ZONE, SECGROUP, VDC, VROUTER, MARKETPLACE, MARKETPLACEAPP, VMGROUP, VNTEMPLATE, BACKUPJOB |
| Permission bits |
Owner / group / other x use / manage / admin (onevm chmod <id> 640) |
| Template instantiation |
Needs USE on the template (7.4 dropped an erroneous CREATE requirement) |
Published Benchmarks
gRPC vs XML-RPC (official, 7.2 docs). Synthetic single-zone load: 1,250 hosts, 20,000 VMs, 10 KB average VM template, concurrent mix of host.info, hostpool.info, vm.info, vmpool.info. Average response time in seconds:
| API call |
XML-RPC 10 req/s |
gRPC 10 req/s |
XML-RPC 30 req/s |
gRPC 30 req/s |
host.info |
0.01 |
0.01 |
0.07 |
0.02 |
hostpool.info |
0.07 |
0.02 |
0.17 |
0.03 |
vm.info |
0.02 |
0.01 |
0.07 |
0.02 |
vmpool.info |
0.97 |
0.43 |
2.15 |
0.94 |
Hardware for the test is not stated in the docs. No independent benchmark was found.
Hardening Checklist
Known Pitfalls
| Pitfall |
Risk |
Mitigation |
oneadmin used for daily work |
Full-cloud compromise on credential leak |
Named admin users in the oneadmin group with LDAP/SAML |
| No security groups on NICs |
VMs exposed to all network traffic |
Default-deny security groups |
Broad ACLs (* ... ADMIN) |
Unauthorized resource access |
Least-privilege ACLs per group |
| VXLAN traffic unencrypted between hosts |
Sniffing on the underlay |
Encrypt the underlay at host level (IPsec/WireGuard configured outside OpenNebula; no native OpenNebula feature confirmed) |
| Unpatched KVM/QEMU |
Hypervisor escape |
Regular host patching |
| Customized fencing script |
Overwritten by package upgrade (7.4 known issue) |
Restore fence_host.sh from /var/lib/one/backups/config/ after upgrade |
Sources