ZStack Cloud 5.1.8

Highlights

  • Enhanced GPU O&M:
    • Provides a new page called GPU Device to help you in GPU centralized management.
    • Supports GPU real-time monitoring and prompt alarms.
  • Enhanced L3 Network O&M: Supports for modifying DHCP service configurations and reserving IP ranges for L3 networks.
  • Supports Host Hardware Monitoring: Monitors and displays host hardware status. Sends alarm messages once hardware abnormalities are detected.
  • Optimized Message Log: Supports for viewing real client IP in operation log and audit.

Overview

VM Instance
  1. Supports for sorting VMs by IP address.
  2. Enhances the VM GuestTools compatibility with more GuestOS.
Cloud Network
  1. Enhanced L3 network O&M.
    1. Supports for modifying DHCP service configuration.
    2. Supports for reserving IP range for L3 network.
    3. Supports IP conflict detection.
  2. Customize network configurations for cloned VMs: assigning IPs, managing NICs, and more.
Platform O&M
  1. Enhanced GPU O&M.
    1. A new page called GPU Device that helps you in centralized GPU managements.
    2. Detailed information on the GPU Device page.
    3. Real-time GPU monitoring and prompt alarms.
    4. A new sub-page called Physical GPU Device on elastic baremetal details page.
  2. Host hardware monitoring.
    1. Monitors and displays host hardware device status.
    2. Supports more host hardware alarm metrics, sending alarm messages promptly when abnormalities occur.
  3. Optimized message log.
    1. Provides real client IP information in operation logs and audit logs.
    2. Removes limit on the number of displayed audit logs on the UI.
    3. Optimizes the log severity level setting for log servers.
  4. Enhanced monitoring and alarm.
    1. SMS endpoint supports Emay Softcom gateway; HTTP Application endpoint is renamed to Webhook.
    2. Enhances availability checking for endpoints.
    3. Supports for modifying more configurations of endpoints.
Tenant Management
  1. Single Sign-On enhancements.
    1. SSO rename.
    2. Supports specifying scope for OIDC or OAuth2 servers.
    3. Supports integrating with ZFIAM, Alibaba Cloud IDaaS (Private), MaxKey SSO system.
Backup Management
  1. Supports Full Backup Policy backup mode for backup jobs.
Cryptography Security Compliance
  1. Supports China Telecom Quantum Technology Service Platform.
  2. Supports FiSEC, SanSEC, and FLKSEC signature verification servers.
License Management
  1. Support for uploading and managing add-on licenses: Container Service-CPU and Container Service-vCPU.

VM Instance

Supports for Sorting VMs by IP Address

Starting from ZStack Cloud 5.1.8, you can sort VM instances by IPv4 address. This helps you view VM instances more efficiently and intuitively, and optimizes the large-scale VM instance management experience.
  • You can sort VM instances by ascending or descending order.
  • VM instances with multiple NICs are sorted according to their default NIC.
  • VM instances without IPv4 address are placed last when sorted in ascending order and first when sorted in descending order.
图 1. VMs Ordered by IPv4


Enhances the VM GuestTools Compatibility with More GuestOS

In previous versions, ZStack Cloud provided a VM GuestTools. This tool consists of various utilities that enhance VM instance performance and expand VM functionalities, such as QGA and internal monitoring agent. Installing the GuestTools makes the VM support extended features, including VM internal monitoring, configuration synchronization, and configuration reading.

Starting from ZStack Cloud 5.1.8, VM GuestTools becomes compatible with more GuestOS.
GuestOS Type GuestOS that is already compatible with GuestTools in previous versions GuestOS that become compatible with GuestTools in 5.1.8
CentOS
  • CentOS 6.5
  • CentOS 6.8
  • CentOS 6.9
  • CentOS 6.10
  • CentOS 7.2
  • CentOS 7.3
  • CentOS 7.4
  • CentOS 7.5
  • CentOS 7.6
  • CentOS 7.9
  • CentOS 6.6
  • CentOS 6.7
  • CentOS 8.0
  • CentOS 8.1
  • CentOS 8.2
  • CentOS 8.3
  • CentOS 8.4
  • CentOS 8.5
  • CentOS Stream 8
  • CentOS Stream 9
RHEL
  • RHEL 6.9
  • RHEL 7.4
  • RHEL 7.5
  • RHEL 7.6
  • RHEL 7.0
  • RHEL 7.1
  • RHEL 7.2
  • RHEL 7.3
  • RHEL 7.7
  • RHEL 7.8
  • RHEL 7.9
  • RHEL 8.0
  • RHEL 8.1
  • RHEL 8.2
  • RHEL 8.3
  • RHEL 8.4
  • RHEL 8.5
  • RHEL 8.6
  • RHEL 8.8
  • RHEL 8.9
  • RHEL 8.10
  • RHEL 9.0
  • RHEL 9.2
  • RHEL 9.4
Fedora
  • Fedora 30
  • Fedora 31
/
Debian
  • Debian 9.9
  • Debian 10.13
  • Debian 11.9
  • Debian 12.5
Ubuntu
  • Ubuntu 14.04
  • Ubuntu 16.04
  • Ubuntu 16.10
  • Ubuntu 18.04
  • Ubuntu 20.04
  • Ubuntu 20.04
  • Ubuntu 24.04
Kylin
  • Kylin V4.0.2
  • Kylin V10 SP1(0518)
  • Kylin V10 SP2
  • Kylin V10 SP3
NeoKylin
  • NeoKylin V7.0
  • NeoKylinV7update6
/
OpenSUSE
  • OpenSUSE Leap 15.0
/
SLES
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Desktop 12
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Desktop 15
  • SUSE Linux Enterprise Server 11
UOS
  • UOS V20 1050e
/
oracle linux
  • oracle linnux 7.9
/
FreeBSD
  • FreeBSD 11
  • FreeBSD 12
  • FreeBSD 13
/
OpenEuler
  • OpenEuler 20
  • OpenEuler 22
/
Windows
  • Windows 10
  • Windows Sever 2008 R2
  • Windows Server 2012
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server2022
/
Rocky /
  • Rocky 8.8
  • Rocky 8.9
  • Rocky 9.4
Anolis /
  • AnolisOS 8.6
  • AnolisOS 8.8
Alma Linux /
  • Alma Linux 9.3
  • Alma Linux 9.4

Cloud Network

Enhanced L3 Network O&M

Supports Modifying DHCP Service Configuration

Starting from ZStack Cloud 5.1.8, you can enable or disable DHCP service in flat networks and public networks. The modification takes effect right away. This allows you to match network needs or maintenance plans by adjusting the DHCP service state. Also, you can change the IP of the DHCP service in these networks, making network control more flexible.
图 1. Modify DHCP Service


Supports Reserving IP Range for L3 Network

Starting from ZStack Cloud 5.1.8, you can add a reserved network segments to L3 networks. The IP addresses in this segment will not be automatically assigned by the platform to new resources or services. This helps in more detailed network planning and IP resource management.
图 2. Reserve IPv4 Range


Supports IP Conflict Detection

Starting from ZStack Cloud 5.1.8, when you assign an IP to a single VM instance during creation or during clone, or change the DHCP service IP, the system checks if the IP is already in use. This prevents IP conflicts that may affect businesses. The IP conflict detection works only with IPv4 addresses.
图 3. IP Conflict Detection


Customizes Network Configurations for Cloned VMs: Assigning IPs, Managing NICs

ZStack Cloud 5.1.8 adds new support for network configuration when cloning a VM instance. By default, the cloned VM instance gets the same network settings as the source VM instance. You can add more networks or adjust the network configurations as needed.
  • You can enable or disable NICs of the cloned VM instances. This allows you to set up the network based on your deployment needs.
  • When you clone a single VM instance, you can assign an IP address. The system checks for IP conflict automatically. This makes using DHCP or static IP setups quicker and simpler.
图 1. Support Network Configuration in VM Cloning


Platform O&M

Enhanced GPU O&M

A New Page Called GPU Device that Helps You in Centralized GPU Managements

Starting from ZStack Cloud 5.1.8, on the Resource Center > Hardware menu, a new page called GPU Device is added. This page shows all physical GPUs and vGPUs in the current zone, including those in KVM clusters and elastic baremetal clusters. On the left side of the page, a directory tree is provided, through which you can quickly find GPU devices you need by the clusters, host/baremetal nodes, or instances they reside on. At the top of the page, you can get a summary of status and distribution of GPU devices.

The GPU Device page is an interface for you to manage GPU devices in a centralized way. On this page, you can conveniently perform actions on all GPU devices, such as editing GPU name, enabling/disabling GPU, setting GPU sharing mode, virtualizing GPU, and restoring GPU. You can also customize the information items displayed in the GPU main list and export GPU information as needed. All of these improves your GPU O&M efficiency.

图 1. GPU Device Page | Directory Tree


Detailed Information on GPU Device Page

The GPU Device page provides rich and detailed GPU information, including the GPU manufacturer, GPU model, GPU type, GPU memory, attached instances, and more. This helps O&M staff get the basic situation of GPU devices quickly and locate and perform troubleshooting in time when problems occur.
图 2. Rich and Detailed GPU Info


Real-Time GPU Monitoring and Prompt Alarm

ZStack Cloud monitors GPU device status and loads in real-time. On the GPU Device main list or the GPU details page, you can view real-time monitoring data such as GPU temperature, GPU utilization, memory utilization, power consumption, fan RPM, PCIe RX I/O, and PCIe TX I/O.

In addition, ZStack Cloud provides GPU alarm metrics that work together with the GPU monitoring. Once an abnormality is detected, such as a high GPU temperature, high GPU utilization, and GPU fault, an alarm message is sent to your endpoint in time, mentioning you to deal with problems that has occurred or may occur to prevent or reduce business risks.

图 3. GPU Status and Load Monitoring


图 4. GPU Resource Alarm Metrics


图 5. GPU Event Alarm Metrics


图 6. GPU Alarm Message


A New Sub-Page Called Physical GPU Device on Elastic Baremetal Details Page

Starting from ZStack Cloud 5.1.8, the details page of elastic baremetal nodes and elastic baremetal instances is added with a physical GPU device list. Unlike the GPU Device page, this entry is used to manage GPU devices on a particular elastic baremetal node or instance. In previous version, hosts have had such an entry for individual GPU managements on their details pages.

Host Hardware Monitoring

Monitors and Displays Host Hardware Device Status

Starting from 5.1.8, ZStack Cloud can obtain host hardware info and health status. Enter the host details page, you can view the host hardware overview, hardware quantity, and hardware health status. The following hardware devices can be detected and monitored: CPU, memory, hard disk, RAID controller card, power supply slot, fan, temperature sensor, physical GPU, and vGPU. If a hardware fault occurs, you can click the corresponding hardware card to view the fault details.

图 1. Host Hardware Status


图 2. Host Hardware Info


图 3. Hardware Fault Details


Supports More Host Hardware Alarm Metrics, Sending Alarm Messages Promptly when Abnormalities Occur

ZStack Cloud 5.1.8 adds a number of new host hardware alarm metrics, such as Host CPU Status Abnormal, Host Memory Status Abnormal, Host Memory ECC Error, Host Disk Status Abnormal, Host Disk is Plugged in/Removed, RAID Card Status Abnormal, GPU/vGPU Atatus Abnormal, GPU is Removed/Disconnected, Power Supply Slot Status Abnormal, Fan Status Abnormal, and more.

These metrics cover a variety of host hardware abnormal scenarios. When errors occur, alarm notifications are pushed to your endpoint promptly, helping O&M staff timely grasp, prevent, or repair hardware problems to avoid causing business impact.

图 4. Host Hardware Event Alarm


图 5. Host Hardware Resource Alarm(Take CPU Temperature as an Example)


Optimized Message Log

Provides Real Client IP Info in Operation Logs and Audit Logs

Starting from ZStack Cloud 5.1.8, the original Browser filed on the Operation Log and Audit (Login Operation) page is changed to a new field called Client IP. The Audit (Resource Operation) page also has this new field added. The Cloud detects and displays the real client IP that initiate operation requests, including both UI and API/CLI operations, in this field. Combined with the IP blocklists and allowlists you set in Access Control, the Cloud now can perform the access control more accurately and further ensure the platform and resource security.

If you are using load balancing to forward requests to the Cloud platform, ensure that the X-Forward-For field is correctly configured on your load balancing device. This allows the Cloud platform to obtain the real client IP address. If not properly configured, the Cloud platform will mistakenly identify the load balancer's IP as the client IP, which can affect the accuracy of log information and access control.

图 1. Operation Log Client IP


图 2. Audit Client IP


Removes Limit on the Number of Displayed Audit Logs

In previous versions, ZStack Cloud can only display a maximum of 300 audit logs on the UI. Starting from ZStack Cloud 5.1.8, the limit on the number of audit logs is removed. You can view all the platform's audit logs on the UI, even if you have more than 10 million logs. To locate the log you need, you can specify a time range or search it by the event name, operated resource, operator, or client IP

Optimizes Log Severity Level Setting for Log Servers

ZStack Cloud 5.1.8 improves the log severity level settings for log servers. Starting form this version, the log server supports 7 log severity levels, ranging from least to most severe: All, TRACE, DEBUG, INFO, WARN, ERROR, and FATAL.

Log severity levels are decided based on the log content and corresponding influence. You can choose to receive logs of a specific level and above. For example, selecting WARN means receiving logs of WARN, ERROR, and FATAL levels, while selecting ALL means receiving all logs.

The original Log Identifier parameter is renamed to Log Facility. Options available are LOCAL0 to LOCAL7. These options are used to match the device that receives the logs. This selection must be consistent with the settings in the rsyslog.conf file of the log server to ensure that the log server can properly receive log messages from the Cloud platform.

Enhanced Monitoring and Alarm

SMS Endpoint Supports Emay Softcom Gateway; HTTP Application Endpoint is Renamed to Webhook

Emay Softcom SMS Endpoint

Starting from ZStack Cloud 5.1.8, the platform supports sending alarm messages to mobile devices via Emay Softcom SMS gateway. You can create a message template of the Universal SMS type to make Emay Softcom SMS messages sent out in a unified format.
图 1. Emay Softcom SMS Endpoint


图 2. Universal SMS Message Template


HTTP Application Renamed to Webhook

The original HTTP Application endpoint type is now renamed to Webhook, which continues to support sending alarm messages to a customized Webhook address via HTTP POST.
图 3. Webhook Endpoint


图 4. Webhook Message Template


Enhances Availability Checking for Endpoints

Supports for Sending Test Messages to Email, SMS, and Webhook Endpoints

In previous versions, the platform has already supported for sending test messages to Dingtalk, WeCom, Lark, and Microsoft Teams endpoints.

Starting from ZStack Cloud 5.1.8, the test message feature is compatible with more endpoint types, such as Email, SMS, and Webhook. This allows you to test whether the platform messages can be sent and received properly before starting to use endpoints, which prevents any missed alarm notifications due to messaging issues after deployment.

图 5. Send Test Message


Endpoint Page Now Shows Connectivity Status Between Endpoint and Cloud

Starting from ZStack Cloud 5.1.8, a new endpoint status column is added to the endpoint main list, visually indicating whether the Cloud platform is connected properly with the endpoint.

UP indicates that the endpoint is connected to the Cloud platform. DOWN indicates that the endpoint is not connected to the management node IP, VIP, or UI service port of the Cloud platform and you need to adjust your endpoint network configurations promptly before you use these endpoints.

图 6. Endpoint Connection Status


Supports for Testing Connection When Adding Email Servers

Starting from ZStack Cloud 5.1.8, a Test Connection button is added on the Adding Email Server page. The email server must pass the connection test before it can be added successfully. This further reduces the risk of email endpoints failing to receive alarm messages normally.
图 7. Test Connection When Adding Email Server


Supports for Modifying More Configurations of Endpoints

Starting from ZStack Cloud 5.1.8, you can enter the endpoint details page to modify a number of configurations to improve alarm O&M flexibility.

Supported configurations for modification include:
  • DingTalk: Message Language, Mention Member, Address, and Security Setting.
  • WeCom: Message Language, Mention Member, and Address.
  • Lark: Message Language, Mention Member, Address, and Security Setting.
  • Microsoft Teams: Message Language and Address.
  • Email: Message Language, Email Address, Email Server.
  • Webhook: Address, Username, and Password.
  • Microsoft Teams: Message Lanuage and Address.
  • SMS (Alibaba Cloud): AccessKey and Add/Delete Phone Number.
  • SMS (Emay Softcom): Appid, SecretKey, and Add/Delete Phone Number.
  • SNMP Trap Receiver: SNMP Trap Receiver.

Tenant Management

Single Sign-On (SSO) Enhancements

SSO Rename

Starting from ZStack Cloud 5.1.8, Third-Party Authentication is renamed to Single Sign-On (SSO).

Supports Specifying Scope for OIDC or OAuth2 Servers

Starting from ZStack Cloud 5.1.8, when you add a OIDC- or OAuth2-typed SSO server, you can specify the Scope parameter. The Scope parameter defines the range of user attributes, such as name or email, to get when requesting access tokens or ID tokens. After setting the Scope, the returned token includes the matching attributes. This makes it easier for admin to manage and control access attributes for different users.
图 1. Specify Scope when Creating SSO Server


Supports Integrating with ZFIAM, Alibaba Cloud IDaaS (Private), MaxKey SSO System

Starting from ZStack Cloud 5.1.8, when you add a OIDC- or OAuth2-typed SSO server, you can specify the Identity Provider (IdP) parameter. This reduces the cost to fit authentication vendors in certain industries. Now, ZStack Cloud supports common IdPs: Default, ZFIAM, Alibaba Cloud IDaaS (Private), and MaxKey SSO System.
图 2. Specify IdP when Creating SSO Server


Backup Management

Supports Full Backup Policy Backup Mode for Backup Jobs

ZStack Cloud 5.1.8 adds a new backup mode that does only full backups. When you create a backup job, you can select the Full Backup Policy option for the backup mode. This backup mode meets the need of specific users who do not want the backup chain to be too long in low-frequency backup scenarios.
图 1. Select Full Backup Policy for Backup Mode


Cryptography Security Compliance

Supports China Telecom Quantum Technology Service Platform

Starting from ZStack Cloud 5.1.8, the Cryptography Security Compliance module supports integration with China Telecom Quantum Technology Service Platform to provide certificate login and data protection service.
图 1. Add China Telecom Quantum Technology Service Platform


Supports FiSEC, SanSEC, and FLKSEC Signature Verification Servers

Starting from ZStack Cloud 5.1.8, the Cryptography Security Compliance module supports integration with FiSEC, SanSEC, and FLKSEC signature verification servers to provide certificate login and data protection service.
图 1. Support FLKSEC, FiSEC, and SanSEC Signature Verification Server


License Management

Support for Uploading and Managing Add-on Licenses: Container Service-CPU and Container Service-vCPU

ZStack Cloud 5.1.8 adds support for two new add-on licenses: Container Service-CPU and Container Service-vCPU. You can now upload and manage these two add-on licenses on the License Management page. With either of these two licenses, you can use the enterprise container service features, such as multi-tenancy, multi-cluster, resource quota, CI/CD, and microservice governance.
图 1. New Add-on License Container Service-CPU and Container Service-vCPU