ZStack Cloud 5.3.28

Highlights

  • OVS-DPDK Network Architecture Enhancements: Supports network services including QoS, DHCP, and security group and optimizes OVS bond mode to cover more business scenarios.
  • Load Balancer Advanced Monitoring: Provides comprehensive monitoring metrics and detailed connection statistics with multi-dimensional filtering and visualization capabilities, improving network O&M efficiency.
  • New Plugin Management Feature: Supports plugin-based integration of cryptographic security compliance and Single sign-on resources, achieving efficient resource integration and deployment to enhance platform agility and scalability.

Overview

VM Instance & Volume
  1. Supports filtering data volumes by instance.
Cloud Network
  1. OVS-DPDK network architecture enhancements.
    1. OVS-DPDK network now supports QoS, DHCP, and security group.
    2. OVS bond mode optimization.
  2. New SDN network plus license.
  3. Introduces load balancer advanced monitoring.
    1. Supports rich monitoring metrics with multi-dimensional filtering.
    2. Supports detailed and visualized connection statistics.
Cloud Storage
  1. SharedBlock storage supports hot migration of data volumes.
  2. Primary storage supports displaying physical storage utilization.
Platform O&M
  1. Supports default Base64 encoding for scripts.
Operational Management
  1. Introduces new applications in Application Market.
Tenant Management
  1. Supports flexible integration of SSO servers.
Cryptography Security Compliance
  1. Supports flexible integration of cryptographic resource.
  2. Enhances compatibility with UKeys.
  3. Optimizes process of enabling certificate login.
  4. Supports choosing cryptographic resource usage.
  5. Supports integrity protection for user-role binding.
Platform & System Setting
  1. Plugin management.
    1. Supports plugin uploading and lifecycle management.
    2. Empowers flexible resource integration and expansion.
  2. Advanced monitoring server.
    1. Supports lifecycle management of advanced monitoring server.
    2. Empowers resource monitoring expansion.
  3. Supports log server dedicated for receiving Cloud operation logs.

VM Instance & Volume

Supports Filtering Data Volumes by Instance

ZStack Cloud 5.3.28 supports filtering data volumes by instance, allowing you to quickly locate data volumes attached to a specified instance.

Figure 1. Filter Data Volume by Instance


Cloud Network

OVS-DPDK Network Architecture Enhancements

ZStack Cloud 5.3.28 introduces the following enhancements to the OVS-DPDK network architecture.

OVS-DPDK Network Now Supports QoS, DHCP, and Security Group Services

Starting from ZStack Cloud 5.3.28, OVS-DPDK network architecture supports network services such as QoS, DHCP, and security group.
  • QoS: Supports bandwidth threshold configuration for flat network NICs, allowing flexible bandwidth allocation based on business requirements to prevent network congestion and ensure smooth operation of critical services.
  • DHCP: Supports DHCP service configuration to automatically assign IP addresses to VMs, significantly improving network deployment efficiency.
  • Security Group: Implements inbound and outbound access control policies for NICs to allow or deny specific traffic, further enhancing network security.

OVS Bond Mode Optimization

ZStack Cloud 5.3.28 optimizes OVS bond mode, now supporting the following three types: Active-Backup, Balance-SLB, and Balance-TCP.

New SDN Network Plus License

ZStack Cloud 5.3.28 introduces the SDN plus license. This license authorizes hardware SDN network integration and advanced network service management capabilities based on OVS-DPDK software networks.

The following features require a SDN network license:
  • Add hardware SDN controllers
  • Create HardwareVxlanNetworks
  • Create hardware SDN-type VXLAN Pools
Figure 1. SDN Network Plus License


Introduces Load Balancer Advanced Monitoring

ZStack Cloud 5.3.28 introduces advanced monitoring for load balancers. Add an advanced monitoring server and enable Advanced Monitoring on the load balancer's details page, you can view comprehensive and intuitive monitoring charts.

Currently, you can view advanced monitoring for HTTP and TCP listeners of load balancers.

Supports Rich Monitoring Metrics with Multi-Dimensional Filtering

The Advanced Monitoring page displays key performance indicators of a load balancer through intuitive line charts, including inbound/outbound traffic, active connections, and concurrent connections, and supports filtering based on time span, client IP, frontend IP, and backend server IP for quick data location. This enables O&M personnel to gain deep insights into the load balancer's performance, promptly identify anomalies, and proactively address potential risks.

Supports Detailed and Visualized Connection Statistics

The Advanced Monitoring page provides a detailed visualization of connection statistics for a load balancer in a structured list format, including access time, listener, client IP, front IP, backend server IP, status code, inbound traffic volume, outbound traffic volume, active connections, and concurrent connections. By presenting data visually, the page enhances O&M convenience and assists O&M personnel in tracing traffic sources, identifying abnormal traffic, and ensuring business stability.

Figure 1. Load Balancer Advanced Monitoring


Cloud Storage

SharedBlock Storage Supports Hot Migration of Data Volumes

ZStack Cloud 5.3.28 introduces hot migration for SharedBlock data volumes. You can now migrate SharedBlock data volumes to other SharedBlock storage while VM instances remain running.

Primary Storage Supports Displaying Physical Storage Utilization

ZStack Cloud 5.3.28 now displays physical storage utilization in the primary storage list, allowing users to promptly identify potential storage space shortages and take preventive measures to avoid failures.

Figure 1. Primary Storage Displays Physical Storage Utilization


Platform O&M

Supports Default Base64 Encoding for Script

Starting form ZStack Cloud 5.3.28, the platform Base64-encodes script content by default when you create a script in Script Library, further improving the data storage and transmission security and ensuring the script compatibility.

Operation Management

Introduces New Applications in Application Market

ZStack Cloud 5.3.28 introduces three new applications in Application Market, including Kylin-V10-SP3, ZStack AI Model Platform, and ZStack CMP. These applications support one-click deployment and quick usage, further enhancing the platform's scalability and helping enterprises accelerate digital transformation.

Figure 1. New Applications


Tenant Management

Supports Flexible Integration of SSO Servers

ZStack Cloud 5.3.28 introduces support for packaging SSO server connection information as standardized plugins for upload, enabling the addition of various types of SSO servers to provide SSO services. This resolves compatibility differences between different server vendors, reduces server adaptation costs, and enhances platform flexibility and scalability.

The platform currently supports plugin-based integration with SSO servers using OIDC and OAuth2 protocols.

Cryptography Security Compliance

Supports Flexible Integration of Cryptographic Resource

ZStack Cloud 5.3.28 introduces a plugin-based method for adding cryptographic resources. This method involves encapsulating resource connection information into a standardized plugin and using this plugin to add the corresponding resource to the Cloud. This enables flexible integration of various cryptographic resources, regardless of the vendor, type, or model, and significantly reduces the adaptation costs and time consumption of enabling Cryptography Security Compliance.

For backward compatibility, ZStack Cloud continues to support the traditional method of adding cryptographic resources by the specified vendor, type, and model. You can choose either method based on your business need.

Figure 1. Add Cryptographic Resource by Plugin


Enhances Compatibility with UKeys

ZStack Cloud 5.3.28 allows you to fill in UKey integration information when enabling Certificate Login with plugin-based cryptographic resources, including the UKey's certificate acquisition interface, signing interface, and the UKey PIN. This flexibility allows you to use various UKey devices for certificate login based on your needs, rather than being limited to UKey devices specified by the Cloud.

Note: For UKey devices adapted using this method, ZStack Cloud does not provide UKey drivers or signature controls. You need to prepare them by yourself.
Figure 1. Configure UKey Adaptation Settings


Optimizes Process of Enabling Certificate Login

Starting from ZStack Cloud 5.3.28, when enabling Certificate Login for admin with plugin-based cryptographic resources, you do not need to enter UKey PIN. Only the certificate serial number is required.

Supports Choosing Cryptographic Resource Usage

Starting from ZStack Cloud 5.3.28, you can specify usage when adding a cryptographic resource to label whether it is intended for Certificate Login, Data Protection, or both Certificate Login and Data Protection.

Figure 1. Choose Cryptographic Resource Usage


Supports Integrity Protection for User-Role Binding

Starting from ZStack Cloud 5.3.28, Data Protection includes integrity protection for the binding relationship between users and roles, further enhancing permission security.

Figure 1. Integrity Protection for User-Role Binding


Platform & System Setting

Plugin Management

Supports Plugin Uploading and Lifecycle Management

ZStack Cloud 5.3.28 introduces the Plugin Management page. On the main menu of ZStack Cloud, choose Setting > System and Security > Plugin Management. Then, the Plugin Management page is displayed. On this page, you can upload and delete plugins.

Figure 1. Plugin Management Page


Empowers Flexible Resource Integration and Expansion

Plugins encapsulates integration information for expanded resources or tools. By developing and uploading standardized plugins, you can quickly integrate and install these resources or tools on the Cloud. This enhances the resource integration agility and boosts the Cloud's scalability.

Currently, ZStack Cloud allows you to use plugins to integrate cryptographic resources and SSO servers.

Advanced Monitoring Server

Supports Lifecycle Management of Advanced Monitoring Server

ZStack Cloud 5.3.28 introduces the Advanced Monitoring Server page. On the main menu of ZStack Cloud, choose Setting > Platform Settings > Advanced Monitoring Server. Then, the Advanced Monitoring Server page is displayed. On this page, you can manage advanced monitoring servers and related images and offerings.

Figure 1. Advanced Monitoring Server Page


Empowers Resource Monitoring Expansion

An advanced monitoring server is a dedicated VM instance used to receive advanced monitoring data of cloud resources. It enables richer monitoring data and more comprehensive metrics.

Currently, you can use an advanced monitoring servers to provide advanced monitoring service for load balancers.

Supports Log Server Dedicated for Receiving Cloud Operation Logs

ZStack Cloud 5.3.28 introduces a new log server type dedicated for receiving Cloud operation logs. The following output types are supported: Syslog, Elasticsearch, Forward, Kafka, and Loki.

Cloud operation log servers support multi-tenant isolation. Each project can have up to one Cloud operation log server which receives only logs of operations performed by the members within that project. This ensures the data isolation and security in multi-tenant scenarios.

Figure 1. Add Cloud Operation Log Server