ZStack Cloud 5.5.0

Highlights

  • Support for Hygon CPU Security Element (SE) Virtualization and Passthrough: Reduces hardware costs and improves security resource utilization by virtualizing and passing through the embedded security coprocessor (CCP) to VM instances. Efficiently meets compliance requirements, including classified cybersecurity protection and cryptography assessment.
  • Dual-NIC Bond Support for SR-IOV Virtualization and Restoration: Enables flexible allocation and high availability of high-performance network resources. It improves network throughput and reduces latency while providing link redundancy and failover capabilities.
  • Supports Batch VM Migration: Migrates multiple VMs to target hosts or primary storage with a single action. Reduces the complexity of large-scale operations such as planned maintenance and storage expansion, and reduces the risk of service interruption.
  • Supports Cross-Platform License Sharing: Helps enterprises improve asset utilization and operational efficiency in multi-environment collaboration scenarios.

Overview

VM Instance
  1. Supports batch configuration of VM console passwords or console modes.
  2. Changes to console password take effect without VM reboot.
  3. Supports batch VM migration.
Cloud Network
  1. Supports SDN Instance HA.
  2. Dual-NIC Bond support for SR-IOV virtualization and restoration.
  3. VPC vRouters support for NIC traffic visualization and monitoring.
  4. Supports specifying primary storage when creating dedicated load balancers.
  5. Load balancer listeners support IP allowlist access control.
Cloud Storage
  1. A single cluster supports more storage combination.
  2. CBD primary storage enhancements.
    • Supports adding multiple storage pools.
    • Supports configuring overcommitment.
  3. Supports specifying volume provisioning types in cross-SharedBlock migration.
GPU Device Adaptation
  1. Supports KUNLUNXIN P800 passthrough, monitoring, and alarms.
  2. Supports Alibaba PPU passthrough, monitoring, and alarms.
Platform Security
  1. Supports two-factor authentication login for AD/LDAP users.
  2. Support for Hygon CPU security element (SE) virtualization and passthrough.
Platform Integration
  1. Supports managing vCenter 8.0.
Licensing
  1. Supports cross-platform license sharing.
User Experience
  1. Supports customizing dashboard card size.
Operational Management
  1. Tenant management project user count statistics optimization.
  2. Billing management supports more currency types.

VM Instance

Supports Batch Configuration of VM Console Passwords or Console Modes

Starting from ZStack Cloud 5.5.0, you can batch configure VM console passwords and switch VM console modes, significantly improving efficiency in large-scale operations.

The batch console password configuration feature also applies to VPC vRouters and Advanced Monitoring Servers.

图 1. Set VM Console Passwords in Bulk


图 2. Set VM Console Mode in Bulk


Changes to Console Password Take Effect Without VM Reboot

Starting from ZStack Cloud 5.5.0, you can modify the console password of a running VM instance. The change takes effect immediately without requiring a reboot, effectively ensuring business continuity and stability.

This optimization also applies to VPC vRouters and Advanced Monitoring Servers.

Note:

This applies only when modifying an existing console password. Adding or removing a console password still require a VM reboot.

图 1. Modifying Console Password Takes Effect Without a Reboot


Supports Batch VM Migration

Starting from ZStack Cloud 5.5.0, you can migrate VM instances in batches, simplifying large-scale operations such as planned maintenance, storage expansion, and load rebalancing. You can specify a common target host or primary storage for a batch VM instances, or specify targets individually, balancing efficiency with operational flexibility.

Additionally, migration entry points are now available on the Associated Resource tab in the host or primary storage details page. This allows you to initiate batch migration directly based on the associated hosts or primary storage, providing richer operational perspectives and a more convenient user experience.

图 1. Migrate VM Instances in Batch


图 2. VM Bulk Migration on Host Details Page (Change Host)


图 3. VM Bulk Migration on Primary Storage Details Page (Change Primary Storage)


Cloud Network

Supports SDN Instance HA

Starting from ZStack Cloud 5.5.0, the SDN module introduces a new resource type: the SDN cluster. An SDN cluster is a group of dedicated VM instances designed to provide highly available SDN capabilities.

Flexible Deployment Modes

When creating an SDN cluster, you can choose one of the following deployment modes based on business requirements:
  1. Cluster Mode (Recommended for production environments)
    • The system automatically creates an SDN cluster containing 3 nodes.
    • All nodes in the cluster have the same instance offering and are deployed on the same primary storage.
    • The system uses an anti-affinity policy to ensure the 3 nodes are scheduled to run on different hosts, effectively preventing network function anomalies caused by host failures.
  2. Single-Node Mode (Suitable for development, testing, or lightweight environments)
    • The system creates a single-node SDN instance, whose behavior is identical to the legacy SDN Instance.

Enhanced Monitoring and Operations

  • Supports visualization and monitoring of the SDN cluster as a whole and its internal nodes. You can intuitively view the health status of the cluster and nodes, facilitating rapid fault identification by operations staff.
  • A new SDN cluster maintenance mode is added. In maintenance mode, you can perform operations such as adding, rebooting, or deleting instances within the cluster.
图 1. Create SDN Cluster


Dual-NIC Bond Support for SR-IOV Virtualization and Restoration

Starting from ZStack Cloud 5.5.0, SR-IOV is supported on dual-NIC bonds. You can configure VF NICs based on dual-NIC bonds for VPC vRouters, thereby achieving both the network performance of hardware passthrough and high availability.

Support for SR-IOV Virtualization and Restoration on Dual-NIC Bonds

When physical NICs are added to a bond and the number of NICs in the bond does not exceed two, you can perform SR-IOV virtualization on the NICs. When you virtualize or restore the physical NIC, all physical NICs in the bond will be virtualized or restored.
图 1. Bond SR-IOV Virtualization


图 2. Bond SR-IOV Restoration


VPC vRouter Support for NIC Traffic Visualization and Monitoring

When creating a VPC vRouter, using a bonded network with SR-IOV enabled provides both the low latency and high throughput of hardware passthrough and the redundancy mechanism provided by bonding. This meets the dual requirements of being both fast and stable for core production business networks.
图 3. Attach Bond Network to VPC vRouter and Enable SR-IOV


VPC vRouters Support for NIC Traffic Visualization and Monitoring

ZStack Cloud5.5.0 adds NIC traffic statistics to the internal monitoring of VPC vRouters, including the following metrics:

  • VRouterNetworkInBytes
  • VRouterNetworkAllInBytes
  • VRouterNetworkInPackets
  • VRouterNetworkAllInPackets
  • VRouterNetworkInErrors
  • VRouterNetworkAllInErrors
  • VRouterNetworkInDroppedBytes
  • VRouterNetworkAllInDroppedBytes
  • VRouterNetworkOutBytes
  • VRouterNetworkAllOutBytes
  • VRouterNetworkOutPackets
  • VRouterNetworkAllOutPackets
  • VRouterNetworkOutErrors
  • VRouterNetworkAllOutErrors
  • VRouterNetworkOutDroppedBytes
  • VRouterNetworkAllOutDroppedBytes
图 1. VPC vRouter NIC Visual Monitoring


Supports Specifying Primary Storage When Creating Dedicated Load Balancers

Starting from ZStack Cloud 5.5.0, dedicated load balancers support specifying a primary storage. When creating a dedicated load balancer, administrators can use the Storage Allocation Policy option to manually select the target primary storage. This allows you to allocate appropriate storage resources to load balancer instances based on business requirements, ensuring their performance in handling network traffic.

图 1. Create Dedicated Load Balancer with Primary Storage Specification


Load Balancer Listeners Support IP Allowlist Access Control

Starting from ZStack Cloud 5.5.0, you can add an IP allowlist in the advanced settings of a load balancer listener. After adding the allowlist, only requests from the specified IP addresses will be permitted to access the load balancer service.

图 1. Add IP Allowlist when Creating Listener


Cloud Storage

A Single Cluster Supports More Storage Combinations

Starting from ZStack Cloud 5.5.0, a single cluster now supports the following additional storage combinations:

  • 1 CBD + multiple SharedBlock
  • 1 CBD + multiple LocalStorage
  • 1 CBD + 1 Ceph
  • 1 Vhost + multiple SharedBlock
  • 1 Ceph + multiple NFS
You can flexibly combine different types of storage resources based on business scenario requirements, enabling more granular storage management.
图 1. CBD + SharedBlock


图 2. CBD + LocalStorage


图 3. CBD + Ceph


图 4. Vhost + SharedBlock


图 5. Ceph + NFS


CBD Primary Storage Enhancements

ZStack Cloud 5.5.0 enhances CBD primary storage with the following features.

Supports Adding Multiple Storage Pools

Starting from ZStack Cloud 5.5.0, you can add multiple storage pools at once when adding CBD primary storage, simplifying multi-pool configuration. Operations for storage pools are also enhanced: you can flexibly add or remove storage pools as needed and set easily identifiable display names for each pool.
图 1. Add Multiple Storage Pools to CBD Primary Storage


Supports Configuring Overcommitment

On the Advanced Settings tab of the CBD details page, you can set an overcommitment ratio for the CBD primary storage. This controls the virtual allocatable space that can be overcommitted when creating volumes on this storage.
图 2. Set Overcommit for CBD Primary Storage


Supports Specifying Volume Provisioning Types in Cross-SharedBlock Migration

Starting from ZStack Cloud 5.5.0, the storage migration feature adds support for custom volume provisioning types. When performing Change Primary Storage or Change Host and Primary Storage operations across SharedBlock Primary Storage, you can use the Volume Provisioning Type option to choose from four strategies: Source Format, Destination Format, Thin Provision, or Thick Provision. This allows you to customize the provisioning type of the volume after migration, ensuring the continuity and consistency of business storage policies during the migration process.

图 1. Specify Volume Provisioning Types


GPU Device Adaptation

Supports KUNLUNXIN P800 Passthrough, Monitoring, and Alarms

ZStack Cloud 5.5.0 now supports KUNLUNXIN P800 passthrough, monitoring, and alarms.

Supports Alibaba PPU Passthrough, Monitoring, and Alarms

ZStack Cloud 5.5.0 now supports Alibaba PPU passthrough, monitoring, and alarms.

Platform Security

Supports Two-Factor Authentication Login for AD/LDAP Users

Starting from ZStack Cloud 5.5.0, AD/LDAP users support two-factor authentication for login. The Two-Factor Verification setting in Global Setting applies to local users, local sub-accounts, and AD/LDAP users. When enabled, these users must authenticate with a two-factor security code before they can log in to the platform, effectively enhancing account security.

Support for Hygon CPU Security Element (SE) Virtualization and Passthrough

Starting from ZStack Cloud 5.5.0, you can virtualize, restore, or passthrough the Hygon CPU’s built-in security coprocessor, granting VMs with Hygon CPU encryption capabilities to ensure computing security. For VMs deployed on Hygon hosts, enabling SE-Based Encryption on the VM creation page or details page automatically assigns an SE device. Disabling SE-Based Encryption automatically removes the SE device.

图 1. SE Device Virtualization and Ungeneration


图 2. SE Device Attached to VM Instance


Platform Integration

Supports Managing vCenter 8.0

Starting from ZStack Cloud 5.5.0, you can manage vCenter 8.0. The full list of supported vCenter versions for management is now: 5.5, 6.0, 6.5, 6.7, 7.0, 8.0.

Licensing

Supports Cross-Platform License Sharing

Starting from ZStack Cloud 5.5.0, you can share licenses across multiple platform. You can upload a license file on any platform and enable License Sharing, configuring it as a license server. Other platforms (shared sites) can then connect to this platform using an AccessKey to share its license quota. This licensing model helps enterprises effectively improve asset utilization and operational efficiency in multi-environment collaboration scenarios.

On the license server, you can centrally view and manage all shared sites, including monitoring site status, synchronizing license information, and removing sites. Each shared site can view license quota and usage in real time, facilitating local operations and cost accounting.

图 1. Cross-Platform License Sharing


User Experience

Supports Customizing Dashboard Card Size

Starting from ZStack Cloud5.5.0, clicking Customize on the Dashboard allows you to drag and change card sizes, increasing the flexibility of the dashboard layout.

图 1. Drag to Resize Card


Operational Management

Tenant Management Project User Count Statistics Optimization

ZStack Cloud 5.5.0 optimizes the tenant management project user count statistics. It now separately displays the number of members, the number of member groups, and the total number of users within the project. The total project user count is calculated as: Total Users = Number of Members + Sum of Individuals in Each Member Group.

图 1. Tenant Management Project User Count Statistics Optimization


Billing Management Supports More Currency Types

Starting from ZStack Cloud5.5.0, support for the following billing currency types has been added: UAE Dirham (AED), Malaysian Ringgit (MYR), Pakistani Rupee (PKR), Saudi Riyal (SAR), Singapore Dollar (SGD), and Thai Baht (THB).

You can select desired currency through the global setting "Billing Currency Symbol." Once configured, relevant bills will be calculated and displayed using the chosen currency symbol.

图 1. Support More Currency Type