Release Notes
This chapter describes the component versions and major releases of ZStack Cloud Foundation (ZCF).
ZStack Cloud Foundation 1.3.0
On September 30, 2026, ZStack Cloud Foundation (ZCF) 1.3.0 was officially released.
Components and Versions
| Component | Version |
|---|---|
| ZStack Cloud | 5.5.38 |
| ZStack ZStone Distributed Storage | 5.5.12 |
| ZStack Zaku Container Cloud Platform | 3.11.0 |
| ZCF Cloud Federation | 1.3.0 |
| ZCF Unified Portal | 1.3.0 |
| ZCF Observability | 1.3.0 |
| ZCF Network Services (ZNS) | 1.3.0 |
| ZCF Installation and Deployment Wizard | 1.3.0 |
Highlights
ZStack Cloud
- Enhanced DPU Elastic Baremetal Capabilities: Extends DPU baremetal instance creation and O&M capabilities with multiple business networks, data volumes, and VNC console management for more high-performance infrastructure scenarios.
- Expanded Monitoring and Alarm Ecosystem Integration: Adds SNMP Trap v2c and v3 support and enables flexible SMS gateway integration through plugins, improving integration with notification channels.
- Time Policies for Security Groups and VPC Firewall Rule Sets: Set effective dates and time periods for rules to run once or repeat weekly, allowing network access policies to take effect or stop taking effect as scheduled for working hours, temporary access, and recurring access control.
Cloud Federation
- Security Service Provisioning, Deployment, and Tenant Management: Eligible tenants can use Unified Portal to provision, deploy, and manage Anheng Log Audit, Bastion, and Host Security EDR in one place, and perform service maintenance operations such as upgrades, renewals, and unsubscriptions.
Observability
- AIOS Inference Service Runtime Observability: Collects metrics, status events, and runtime logs from AIOS inference services, and provides predefined views, dashboards, and weekly reports to help analyze service operation.
- Alarm Notifications and Noise Reduction: Extends multichannel alarm notifications and uses silence and inhibition rules to reduce duplicate notifications during maintenance windows and correlated faults.
- Alarm Configuration Consistency Check: Identifies alarm configuration differences between ZCF and connected Cloud or ZSphere platforms and restores configuration consistency as needed.
Network Services
- Cross-Site Network Connectivity: Configure DCI Gateways at both sites, a DCI link, and a Tier-1 peering connection to connect all local subnets or selected subnets as needed.
- Traffic Visibility and Packet Capture: View traffic trends and observed communication relationships by scope and time range, and create packet capture tasks for VM NICs to help investigate network issues.
New Features and Enhancements
This section describes the new and enhanced features in ZCF 1.3.0 by component and capability area.
ZStack Cloud
In ZCF 1.3.0, ZStack Cloud includes the following major updates:
VM Instances
VM Instances Can Reclaim Primary Storage Space After Data Deletion
Supports reclaiming unused disk space after data deletion by using the q35 virtual motherboard and Virtio BLK Discard mechanism in VM instances. This reduces invalid occupancy and improves storage utilization. New eligible VM instances created through the UI use the q35 virtual motherboard by default. For existing VM instances, you can switch to the q35 virtual motherboard in Advanced Settings on the details page when the instance is stopped.
Note: To use this capability, make sure that the following requirements are met:- The cloud platform runs in an H84R environment.
- The primary storage type is local storage or Ceph (ZStone distributed block storage).
- The VM instance architecture is
x86_64; the operating system is Debian 12, Ubuntu 22.04.5, or Ubuntu 24.04.1; and the operating system kernel, Virtio driver, and file system support the Virtio BLK Discard mechanism. - Before changing the motherboard type of an existing VM instance, back up data and check
/dev/vdX, PCI addresses, passthrough devices, and special device topology configurations.
Cloud Networking
Load Balancer Improvements
The following load balancer improvements are added:
Supports Batch Enabling and Disabling Backend Servers
Users can enable or disable one or more backend servers in a load balancer listener. When a server is disabled, the platform no longer distributes new access traffic to it but retains its port, weight, and server group configurations. After the server is enabled again, health checks restore its traffic capacity, enabling rapid traffic removal and recovery during service releases, maintenance, or fault handling.
Supports HTTPS Health Checks
Users can use HTTPS to check the health of load balancer backend servers and configure the check path, request method, expected response status code, check port, and health threshold as needed. This applies to web services that require encrypted probing.
Security Groups and VPC Firewall Rule Sets Support Time Policies
Supports setting time policies for security groups and VPC firewall rule sets. Users can configure effective dates and time periods for rules to run once or repeat weekly, allowing security group rules and rules synchronized to associated firewalls to automatically take effect or stop taking effect as scheduled. This supports scenarios such as access during working hours, temporary authorization, and periodic access control, reducing manual enablement and disablement operations and the risk of omissions.
Each security group or rule set can have multiple time policies, one of which can be selected as the current policy. Rules are not time limited when no current policy is set. Time policies support local time and UTC and provide status display and expiry reminders.
Improves Management Network Dual-Stack Deployment and Access
Improves IPv4/IPv6 dual-stack deployment and access for the management network. Management nodes can be configured with both IPv4 and IPv6 addresses, and users can use either type of address to access the platform UI and API. Other nodes can access the platform through IPv4 or IPv6.
Cloud Storage
ZBS Primary Storage Supports CBT Backup
Adds CBT support for ZBS (CBD protocol) primary storage. Users can perform full backups, incremental backups, and data recovery for root volumes and data volumes of VM instances. This feature requires ZBS 1.9.0.
Ceph Primary Storage Supports Multiple Image Cache Pools
Supports configuring multiple image cache pools in the same Ceph primary storage. Users can add existing physical storage pools as image cache pools and select the image cache pool policy in global settings. The platform selects a cache according to the policy when users create a VM instance, change an image, or reset a root volume, improving image-use flexibility in multi-storage-pool scenarios.
Monitoring and Alarms
Adds VM Instance Running and Stopped State Event Alarms
Adds the VM Instance Entered Running State and VM Instance Entered Stopped State alarm rules. Users can use these rules to create event alarms and track VM instance state changes.
Automatically Acknowledges Alarm and Recovery Messages After Resource Alarm Recovery
Adds the Automatically Acknowledge Alarm Messages After Resource Alarm Recovery global setting. When enabled, related alarm and recovery messages are automatically acknowledged after a resource alarm meets the recovery condition, without manual intervention.
Supports Plugin-Based SMS Gateway Integration
Adds an SMS gateway plugin type. Users can use custom plugins to flexibly integrate various SMS gateway servers and send platform alarm messages by SMS.
SNMP Trap Supports v2c and v3
Adds SNMP Trap v2c and v3 support in addition to existing v1 compatibility, meeting the integration and security requirements of more monitoring platforms.
Elastic Baremetal Management
Enhances DPU Baremetal Instance O&M
Enhances configuration and O&M capabilities for DPU elastic baremetal instances. Users can create instances by offering, configure multiple business networks, IP addresses, and data volumes, and perform O&M operations including start, stop, restart, delete, system reinstallation, and login password changes. Users can also perform O&M through the VNC console and identify and use existing management network bond configurations on the DPU SoC.
Baremetal Nodes Support Tag Management
Supports adding tags to baremetal nodes for resource filtering and classification.
Experience Optimization
Improves VM Instance Migration Task Details
Improves the display of VM instance migration task details. When users view a migration task, they can directly obtain key information about the VM instance, source host, target host, source primary storage, and target primary storage to quickly confirm the migration scope and execution status.
Capability Expansion
Supports the ZMigrate Migration Service
Supports installing and using the ZMigrate migration service through the App Center to migrate VM instances from other platforms to the current platform. VMware source platforms are currently supported.
Cloud Federation
In ZCF 1.3.0, Cloud Federation includes the following major updates:
Security Service Provisioning, Deployment, and Tenant Management
Eligible tenants can use Unified Portal to provision, deploy, and manage Anheng Log Audit, Bastion, and Host Security EDR in one place. Users can select service editions, workload specifications, and resource requirements as needed, and track provisioning, deployment, and change progress through service tasks. After a service is provisioned, users can continue to perform maintenance operations such as upgrades, renewals, and unsubscriptions.
Observability
In ZCF 1.3.0, Observability includes the following major updates:
Observable Data
AIOS Inference Service Runtime Observability
Supports connecting metrics, status events, and startup, application, and access logs from AIOS inference services. Predefined views, dashboards, and weekly reports help administrators analyze inference service status from the perspectives of resources, performance, and runtime logs.
Tenant-Scoped Observability Data Access
Observability data, including metrics, logs, alarms, and reports, is filtered by the current tenant, resource permissions, and management view. Tenant administrators can view data for their tenant and associated resources, while standard tenant users can view metrics and alarms only for resources they are authorized to access.
Alarm Center
Expanded Multi-Product Metric Alarm Coverage
Extends metric alarm coverage for ZStone/ZBS and Zaku. AIOS inference services can be included in centralized alarm management based on connected metrics and status events.
Enhanced Alarm Notifications
Extends notification channels such as Feishu, Slack, Microsoft Teams, and Telegram, and improves delivery reliability and status feedback for existing DingTalk, WeCom, SMS, Webhook, and SMTP email channels.
Alarm Noise Reduction Rules
Supports silence rules based on label matching conditions and time windows, as well as inhibition rules based on source alarms, target alarms, and equal labels. These rules reduce duplicate notifications caused by planned maintenance and correlated faults.
Alarm Configuration Consistency Check
Periodically checks whether alarm configurations on connected Cloud or ZSphere platforms are consistent with ZCF. Platform administrators can also synchronize configurations manually. When a difference is identified, the system applies the configuration saved in ZCF to the corresponding platform and verifies the result, supporting unified alarm integration and notification delivery.
O&M Reports
Custom O&M Reports
Platform administrators can create creator-private report templates based on currently accessible views, and generate O&M reports on demand or on a schedule. Templates can be cloned, edited, and deleted, while generated report records are retained independently.
Network Services
In ZCF 1.3.0, Network Services includes the following major updates:
Cross-Site Network Connectivity
Organize compute Clusters and hosts into sites, and connect service networks across two sites by configuring DCI Gateways at both sites, a DCI link, and a peering connection between Tier-1 gateways. The peering connection can allow all local subnets of both gateways to communicate or limit connectivity to specified local subnet CIDRs. Administrators can check the connection configuration status and test connectivity from the service networks. Cross-site connectivity does not preserve VM private IP addresses, extend Layer 2 networks between sites, or switch application entry points automatically.
Traffic Visibility and Packet Capture
Enable traffic collection on hosts and view sessions, traffic trends, protocol distribution, and rankings by compute manager, Cluster, and time range. Use Traffic Topology and its table to inspect collected communication relationships and flows. Create a packet capture task for a VM NIC with active collection, preview packets, and download a PCAPNG file. Traffic Topology does not show the complete forwarding path, and an empty view does not mean that the service has no traffic.
Streamlined Fabric Configuration and Host Connection
Maintain common Fabric Uplink and VTEP settings for each site. When connecting a host, map logical Uplink members to physical NICs and choose to inherit the common configuration, use a host shared configuration, or use a host dedicated configuration. Administrators can check the configuration source and synchronization status, and resynchronize hosts as needed.
Enhanced Host Network Agent Lifecycle
ZNS installs the network Agent asynchronously on eligible KVM hosts discovered by a compute manager. After a controller starts, ZNS checks and updates the Agent on eligible managed hosts. ZNS monitors the connection status of successfully installed Agents and attempts recovery after a sustained disconnection. The Agent applies host network configuration locally. ZNS updates the host configuration status only after receiving a successful result that matches the current configuration. Administrators can check the Agent and host configuration status in the host details.
Note: In this release, the host-side zns-agent and zns-proxy packages support only x86_64 KVM hosts. Host Agent updates may still be in progress after a ZNS controller upgrade completes. If Agent installation, update, or automatic recovery fails, check the host status and resolve the issue manually.Resolved Issues
This section describes the issues resolved in ZCF 1.3.0 by component and capability area.
ZStack Cloud
In ZCF 1.3.0, ZStack Cloud includes the following resolved issues:
Cloud Networking
Fixes Management Network IP Addresses Not Released After VPC vRouter Creation Fails
Fixes an issue where allocated management network IP addresses were not released after subsequent network address allocation failed during VPC vRouter creation, preventing continued address occupancy.
VM Instances and Migration
Fixes SR-IOV VM Instance Startup Failures on Hygon Hosts
Fixes an issue where a host could become disconnected when a VM instance configured with SR-IOV NIC passthrough started on a Hygon host, improving startup stability for SR-IOV VM instances on Hygon hosts.
Fixes Target Host Capacity Reservation Errors During Live Migration
Fixes an issue where resources reserved on the target host during VM instance live migration were not correctly included in capacity statistics, preventing the reserved resources from being used by other tasks.
Cloud Storage and Backup
Optimizes Coordinated Management of the Cloud Platform and ZStone Vhost Service
Fixes an issue where duplicate management of the Vhost service could cause association failures when ZStone primary storage was connected through the Vhost protocol. After the fix, ZStone deployment manages the Vhost service centrally. ZStack Cloud must be used with ZStone 5.5.12.
Fixes SharedBlock Primary Storage Lock Exceptions on 512e Devices
Fixes an issue where lock exceptions on 512e sector devices in SharedBlock primary storage caused volume creation, attachment, or expansion to fail, improving storage lock recovery reliability.
Optimizes High Availability Protection Checks for Ceph Primary Storage Network Failures
Fixes an issue where a high availability protection service could be incorrectly determined to be available before it was ready when the Ceph primary storage network failed, preventing related high availability operations from continuing when protection conditions are insufficient.
Optimizes Target Network Checks for Online Backup
Optimizes target network checks before online backup to prevent backup target network connection exceptions from affecting running VM instances.
Fixes Concurrent Full Backup Task Exceptions
Fixes an issue where duplicate uploads of shared parent images caused concurrent full backup tasks to fail, improving their stability.
Fixes ImageStore Concurrent Export Stability Issues
Fixes an issue where backup data restoration tasks could fail during concurrent ImageStore export, export cancellation, or image reading, improving data protection task stability.
Security
Security Updates
Updates the operating system kernel to fix the following vulnerabilities: CVE-2026-74684, CVE-2026-43499, CVE-2026-64561, CVE-2026-64600, CNNVD-2025-88283257, CNNVD-2025-25811155, CNNVD-2025-61091425, CNNVD-2025-93979693, and CNNVD-2025-99729243.
