Skip to content

Reference

Scope

Look-up facts for OpenNebula 7.x: releases and support windows, editions, certified platforms, services, ports, drivers, configuration keys, VM states, access-control vocabulary, published benchmarks, and a hardening checklist. Figures are from the official 7.2/7.4 release notes and docs unless noted. For how the pieces fit together see Explanation; for tasks see How-to Guides.

Release History

Version Codename Date Notes
7.4.1 Helix 2026-09-10 Maintenance release (fixes, e.g. live storage migration with NVRAM VMs)
7.4.0 Helix 2026-07-27 Redesigned Sunstone; OneKS and LVM SAN storage move to Community Edition; NVIDIA NICo bare metal (EE); OneBEX backup exporter; Ubuntu 26.04
7.2.1 Dark Horse 2026-05-21 EE maintenance release; OneKS first shipped to EE customers
7.2.0 Dark Horse 2026-04-07 gRPC API, NVIDIA Fabric Manager (EE), storage live migration, Pure Storage FlashArray driver, OneForm, memory encryption, Sunstone 2FA enforcement
7.0.0 Phoenix 2025-07 New scheduler framework + OneDRS; Ruby Sunstone, vCenter, ebtables and legacy hybrid drivers removed
6.10.x Bubble 2024 (6.10.5: 2025-11) FireEdge Sunstone default; OneDeploy; OneSwap; Firecracker, LXD, Docker Machine removed

Date sources

7.2.0/7.2.1 dates come from the OpenNebula Release Schedule wiki as surfaced in search results; 7.4.0 (2026-07-27) and 7.4.1 (2026-09-10) come from release announcements and match the publish dates of the opennebula Ruby gem on rubygems.org (7.4.0 on 2026-07-27, 7.4.1 on 2026-09-09). 7.0.0 was published on rubygems.org on 2025-07-03.

Release Policy and Support Windows

Item Value
Minor (feature) release cadence About every 6 months (7.0 Jul 2025, 7.2 Apr 2026, 7.4 Jul 2026)
Pre-releases Beta builds versioned x.(y-1).80/.85 (e.g. gem 7.3.80.pre, 7.3.85.pre before 7.4)
STS support (EE) 9 months (6 months until the next release + 3 months)
LTS support (EE) At least 36 months; LTS every ~2 years; Extended Life add-on up to 4.5 years
CE maintenance Community Forum support; maintenance (x.y.z) packages are primarily an EE benefit
Which 7.x lines are LTS TBD — not confirmed in sources reachable on 2026-09-25; check the Release Policy wiki

Source: Release Policy wiki, What is OpenNebula EE.

Editions

Community Edition (CE) Enterprise Edition (EE)
License Apache License 2.0 Packages distributed under commercial terms to customers with an active subscription
Access Public repos at downloads.opennebula.io/repo/<version>/... Enterprise repos + Customer Portal
Maintenance releases Limited; upgrade to next minor Every ~3 months, STS/LTS lifecycle
Migration tools opennebula-migration (onedb, onecfg) included since 7.0 Included
EE-only features (7.2/7.4) — NVIDIA Fabric Manager integration, NVIDIA NICo Bare Metal as a Service, Veeam integration, NetApp driver; new LVM subsystem was EE in 7.2
Moved EE to CE Restic backups + Prometheus monitoring (6.10); LVM SAN storage + OneKS (7.4) —

EE feature list changes each release

The EE-only set moves every release (features graduate to CE). Check the "(EE)" markers in the current What's New page before assuming a feature is in CE.

Subscription Pricing

Item Value
Tiers Elemental, Standard, Premium (support hours 9x5 vs 24x7 differ by tier)
Pricing model Base annual fee plus a per-managed-node fee; every managed host needs a subscription at the same level
Published figures A third-party listing (SpotSaaS, 2026) reports Standard at about USD 8,750/yr + ~USD 875 per node and Premium at about USD 13,750/yr + ~USD 1,375 per node. Unverified against the official page, which blocked automated access

Official page: OpenNebula Subscription Plans.

Certified Platforms (7.4)

Component Front-end KVM nodes LXC nodes
RHEL 9, 10 9, 10 —
AlmaLinux 9, 10 9, 10 9, 10
Rocky Linux 9, 10 (via Red Hat packages) 9, 10 9, 10
Ubuntu Server 24.04, 26.04 24.04, 26.04 24.04, 26.04
Debian 12, 13 12, 13 12, 13
SUSE Linux Enterprise 15 15 —
openSUSE 16 16 —
Database SQLite (default) or MariaDB/MySQL from the distro — —

Change from 7.2

7.2 certified Ubuntu 22.04 and 24.04; 7.4 moves to 24.04 and 26.04 and adds Rocky Linux. 7.4 also requires that hypervisors in the same Cluster (and all HA Front-ends) run the same OS distribution and version.

Certified Infrastructure Components (7.4)

Area Component Certified version / models
Storage Ceph Reef 18.2.x, Squid 19.2.x
Storage NetApp ONTAP 9.16.1P1
Storage Pure Storage FlashArray (docs call it "Everpure") Purity 6.7.2
Storage NFS v4.2
Networking 802.1Q, Open vSwitch, iproute2 (VXLAN) Distro versions
Networking NVIDIA Spectrum-X, InfiniBand Supported
GPUs (NVIDIA) Ampere / Ada / Hopper / Blackwell A10-A100; L4, L40, L40S; H100, H200, GH200; B200, B300, GB200, GB300
DPUs NVIDIA BlueField 2, 3
AI accelerators Axelera Metis Server 150p, Edge 130p, embedded modules
Monitoring Prometheus 2.53.1
Backup Restic 0.17.3
Backup Veeam B&R >= 13.0 (7.2 certified 12.3.1)
Billing WHMCS 8.13.1
Kubernetes (OneKS) Kubernetes 1.34.2, 1.33.7

Certified scale: a single oned instance is stress-tested with 500 hypervisors without degradation; that is the maximum recommended size before federating. Some users run on the order of 2,000 hypervisors per instance, and the key-features page cites over 2,500 nodes in production (both depend on storage, networking and monitoring configuration).

Removed and Legacy Components

Component Status Since Replacement
Firecracker driver Removed 6.10 KVM
LXD driver Removed 6.10 LXC
Docker Machine, DockerHub marketplace, Docker Registry Removed 6.10 OneKE / OneKS
TurnkeyLinux marketplace Removed 6.10 LXC marketplace
PostgreSQL backend (tech preview) Removed 6.10 MySQL/MariaDB
Ruby Sunstone Removed 7.0 (legacy in 6.10) FireEdge-based Sunstone
vCenter drivers Removed 7.0 (legacy in 6.10) OneSwap migration to KVM
ebtables network driver Removed 7.0 VLAN-based drivers
Legacy hybrid drivers (ec2, azure, opennebula) Removed 7.0 OneForm cluster provisioning
Import of "wild" VMs Removed 7.0 —
mm_sched scheduler daemon Replaced 7.0 one_sched driver framework (rank + OneDRS)

Front-end Packages and Services

Package Purpose
opennebula oned, scheduler, monitor, core drivers
opennebula-tools CLI
opennebula-fireedge Sunstone web UI server (FireEdge)
opennebula-gate OneGate (VM to OpenNebula API)
opennebula-flow OneFlow multi-VM services
opennebula-ks OneKS Kubernetes service (7.4)
opennebula-migration onedb / onecfg upgrade tools
opennebula-node-kvm / opennebula-node-lxc Hypervisor node setup
opennebula-prometheus, opennebula-prometheus-kvm Prometheus + Grafana integration and exporters
opennebula-swap OneSwap VMware-to-KVM migration
opennebula-guacd Guacamole proxy for remote consoles
systemd service Role
opennebula oned daemon, XML-RPC/gRPC endpoint
opennebula-hem Hook Execution Manager (starts with opennebula)
opennebula-fireedge Sunstone GUI server
opennebula-gate, opennebula-flow OneGate, OneFlow
opennebula-form OneForm cluster provisioning
opennebula-ks OneKS
opennebula-ssh-agent Dedicated SSH agent for oned (no key copying to hosts)
opennebula-showback Periodic showback recalculation
opennebula-prometheus Bundled Prometheus

Network Ports

Port Service
22 SSH (front-end to hosts; drivers run over SSH)
2474 OneFlow
2616 FireEdge / Sunstone (http://<frontend>:2616/fireedge/sunstone)
2633 oned XML-RPC API (/RPC2)
2634 oned gRPC API (7.2+, GRPC_PORT)
2101 oned ZeroMQ event publisher (hooks, OneKS subscriber)
4124 Monitoring daemon (TCP/UDP)
5030 OneGate
10780 OneKS API (default bind 127.0.0.1)
29876 noVNC proxy
5900+ VNC on hypervisor hosts (VNC_PORTS)

Drivers

Subsystem Drivers (7.x)
Virtualization (VMM) kvm (QEMU/KVM via libvirt), lxc
Datastore drivers (-d list: image, file, backup) fs, ceph, lvm, dev, iscsi_libvirt, restic, rsync, netapp, purefa, virtiofs, interactive (7.4 OneBEX), dummy
System DS / transfer (-s list) shared, ssh, local, qcow2, ceph, lvm, fs_lvm, fs_lvm_ssh, netapp, purefa, dummy
Networking (VN_MAD) Linux bridge, 802.1Q, VXLAN, Open vSwitch (incl. SR-IOV switchdev in 7.4), plus Spectrum-X and InfiniBand integrations
Authentication core (user/password + tokens), ssh, x509, ldap, saml (7.0.1+), server_cipher, server_x509
Backup Restic (incl. S3 backend in 7.4), rsync, Veeam (EE), OneBEX interactive export (7.4)

The datastore/transfer lists above come from the default DATASTORE_MAD line in the 7.4 known-issues page.

Key File Locations

Path Purpose
/etc/one/oned.conf Core daemon config (drivers, SCHED_MAD, GRPC_PORT, ONEGATE_ENDPOINT, MAC_GLOBAL_SPACE)
/etc/one/schedulers/one_drs.conf OneDRS defaults (overridable per Cluster via ONE_DRS)
/etc/one/fireedge-server.conf FireEdge / Sunstone server config
/etc/one/oneflow-server.conf OneFlow config (:one_xmlrpc endpoint)
/etc/one/onegate-server.conf OneGate config (:server Sinatra section in 7.4)
/etc/one/oneks-server.conf OneKS config
/etc/one/vmm_exec/vmm_exec_kvm.conf KVM driver defaults (e.g. disk cache mode)
/var/lib/one/.one/one_auth oneadmin credentials (initial password on first start)
/var/lib/one/datastores/<id>/ Datastore directories on front-end and hosts
/var/lib/one/remotes/ Driver scripts synced to hosts (onehost sync)
/var/lib/one/vhost-sockets DPDK vhost-user sockets (7.2+)
/var/log/one/oned.log Core daemon log (appended, not truncated, since 7.4)

Configuration Keys

Key Where Meaning
SCHED_MAD = [ EXECUTABLE = "one_sched", ARGUMENTS = "-t 15 -p rank -o one_drs" ] oned.conf -t threads, -p placement scheduler (rank or one_drs), -o optimizer (one_drs)
SCHED_MAX_WND_TIME, SCHED_RETRY_TIME oned.conf Scheduling-window length and retry interval
MAX_ACTIONS_PER_HOST, MAX_ACTIONS_PER_CLUSTER, ACTION_TIMEOUT, LIVE_RESCHEDS oned.conf Scheduler action throttles and live vs cold reschedule
GRPC_PORT = 2634, GRPC_LISTEN_ADDRESS oned.conf gRPC server (enabled by default in 7.2+)
ENDPOINT_GRPC Zone / HA server Required for gRPC clients in HA or federation
ONEAPI_PROTOCOL=grpc, ONE_GRPC=<ip>:<port>, --grpc CLI env/flag Switch CLI to gRPC
ONE_DRS = [ AUTOMATION, POLICY, *_WEIGHT ] Cluster template OneDRS: manual/partial/full; pack/balance; metric weights
ONEDRS_BLOCKED = "YES" VM user template Exclude a VM from OneDRS migrations (7.4)
PRIORITIZE_STORAGE_MIGRATIONS OneDRS config Prefer datastore over host migrations (7.4)
SCHED_REQUIREMENTS, SCHED_RANK, SCHED_DS_REQUIREMENTS VM template Placement filters and ranking
MIGRATE_AUTO_CONVERGE, MIGRATE_COMPRESSED VM template FEATURES Per-VM live-migration tuning (7.4)
BACKUP_CONFIG/DISK_IDS VM template Back up selected disks only (7.4)
LXC_UNPRIVILEGED = "no" VM template Run a privileged LXC container (default is unprivileged)

VM States

State Meaning Typical trigger
PENDING Waiting for the scheduler onetemplate instantiate, onevm release
HOLD Not schedulable until released onevm hold, instantiate --hold
ACTIVE/PROLOG Transferring disks to the host Scheduler deploy
ACTIVE/BOOT Hypervisor starting the guest After PROLOG, or on resume
ACTIVE/RUNNING Running Boot complete
ACTIVE/MIGRATE Live or cold migration in progress onevm migrate [--live], OneDRS
ACTIVE/SAVE_* Saving memory state onevm suspend, onevm stop
SUSPENDED Memory saved on the host onevm suspend
STOPPED Saved and disks moved back to system DS onevm stop
POWEROFF Guest off, disks stay on host onevm poweroff
UNDEPLOYED Off, disks moved back to system DS, host freed onevm undeploy
ACTIVE/SHUTDOWN then EPILOG Guest shutting down, then cleanup onevm terminate
DONE Finished (kept in DB history) Terminate completes
FAILURE / UNKNOWN Driver error / host unreachable Boot, transfer, or monitoring failure

Access-Control Vocabulary

ACL rule part Values
Rule syntax <user or @group or *> <RESOURCE[+RESOURCE]>/<#id, @group or *> <RIGHTS> (e.g. @105 VM+NET/@100 USE+MANAGE)
Rights USE, MANAGE, ADMIN, CREATE
Resources VM, HOST, NET, IMAGE, USER, TEMPLATE, GROUP, DATASTORE, CLUSTER, DOCUMENT, ZONE, SECGROUP, VDC, VROUTER, MARKETPLACE, MARKETPLACEAPP, VMGROUP, VNTEMPLATE, BACKUPJOB
Permission bits Owner / group / other x use / manage / admin (onevm chmod <id> 640)
Template instantiation Needs USE on the template (7.4 dropped an erroneous CREATE requirement)

Published Benchmarks

gRPC vs XML-RPC (official, 7.2 docs). Synthetic single-zone load: 1,250 hosts, 20,000 VMs, 10 KB average VM template, concurrent mix of host.info, hostpool.info, vm.info, vmpool.info. Average response time in seconds:

API call XML-RPC 10 req/s gRPC 10 req/s XML-RPC 30 req/s gRPC 30 req/s
host.info 0.01 0.01 0.07 0.02
hostpool.info 0.07 0.02 0.17 0.03
vm.info 0.02 0.01 0.07 0.02
vmpool.info 0.97 0.43 2.15 0.94

Hardware for the test is not stated in the docs. No independent benchmark was found.

Hardening Checklist

  • Change the initial oneadmin password (seed /var/lib/one/.one/one_auth before first start, later oneuser passwd) and keep oneadmin for administration only.
  • Put Sunstone (port 2616) behind a TLS-terminating reverse proxy; do not expose 2633/2634 publicly.
  • Enforce Sunstone 2FA globally (7.2+).
  • Use LDAP or SAML for people; restrict core password users to service accounts.
  • Least-privilege ACLs per group; use VDCs to scope groups to clusters, datastores and networks.
  • Attach default-deny security groups to every NIC; open only needed ports.
  • Keep LXC containers unprivileged (default); avoid LXC_UNPRIVILEGED = "no".
  • Use VM memory encryption and vTPM (7.2+) for confidential or regulated workloads.
  • Rely on opennebula-ssh-agent rather than copying the oneadmin private key to hosts.
  • Patch KVM/QEMU/libvirt on hosts regularly; keep front-end and hosts on certified OS versions.
  • Back up the database (onedb backup) and /etc/one before every upgrade.
  • Restrict permissions on /etc/one/ and /var/lib/one/.one/.

Known Pitfalls

Pitfall Risk Mitigation
oneadmin used for daily work Full-cloud compromise on credential leak Named admin users in the oneadmin group with LDAP/SAML
No security groups on NICs VMs exposed to all network traffic Default-deny security groups
Broad ACLs (* ... ADMIN) Unauthorized resource access Least-privilege ACLs per group
VXLAN traffic unencrypted between hosts Sniffing on the underlay Encrypt the underlay at host level (IPsec/WireGuard configured outside OpenNebula; no native OpenNebula feature confirmed)
Unpatched KVM/QEMU Hypervisor escape Regular host patching
Customized fencing script Overwritten by package upgrade (7.4 known issue) Restore fence_host.sh from /var/lib/one/backups/config/ after upgrade

Sources