Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Servidores de rack idénticos apilados en un carro metálico, pendientes de montar, delante de un rack a medio poblar
8 min read

Corosync adds 650 milliseconds per node: the clock your upgraded cluster is still carrying

The time a Proxmox cluster takes to re-form membership after losing a node is not fixed: it grows by 650 ms for every node you add, and on factory values a 29-node cluster reaches 45.21 seconds — exactly where the documentation itself asks you to fix it, before the 60-second watchdog starts rebooting healthy nodes. Proxmox VE 9.2 lowered it to 125 ms, but only when the cluster is created: clusters upgraded from 8 to 9 keep the old value.

Servidor de almacenamiento abierto en un rack con las bahías de discos a la vista y una unidad extraída de su carro
9 min read

In Ceph, capacity is not set by the cluster: it is set by the fullest disk

A single OSD above 95% stops writes across the whole cluster even while "ceph df" still shows dozens of free terabytes. The three default thresholds (0.85 / 0.90 / 0.95), why the mechanism that repairs switches off five points before the one that serves, and the capacity calculation with one node missing that almost nobody runs: with four nodes the ceiling is 71 points, and 67 if you want the rebuild to actually finish.

Dos routers de operador montados en un rack con latiguillos de fibra de dos colores llegando desde bandejas distintas
8 min read

Two ISPs are not redundancy if the ISP owns the IP

A second line saves what leaves the office, not what comes in: when the main one drops, the IP address changes, and with it DNS, open sessions, tunnels and third-party allow lists. The three real ways to have two paths, with 2026 figures: EUR 1,800 a year in RIPE fees, EUR 50 for the ASN, roughly 7,700 to 10,200 dollars for the /24 itself, and the ninety-second default of the BGP hold timer.

Armario de red mural con la puerta abierta en el cuarto trastero de una oficina, con cajas de cartón, una fregona y estanterías
7 min read

Gitea's flaw "requires write access". The signup form hands it to you

The CVE-2026-60004 write-up says you need write access to a repository. The official vector in the same advisory says <code>PR:N</code>, privileges required: none. Both are true, because Gitea installs with <code>DISABLE_REGISTRATION=false</code>. What that means for how you prioritise patching everything you self-host, what happened in the eleven seconds of the only public case, and the list of what to check today.

Pasillo de un centro de datos con un rack abierto a medio poblar y un carro elevador con un servidor encima
8 min read

When NOT to migrate from VMware to Proxmox

Migrating from VMware to Proxmox is part of what we do, and there are cases where our answer is: not now. Two classic objections no longer hold — the scheduler's dynamic mode arrived with Proxmox VE 9.2 on 21 May, and Veeam 13.1 has shipped replication since 29 July. The one still standing is different: Proxmox's HA documentation describes nothing equivalent to vSphere's <em>admission control</em>, which flatly refuses to power on the machine that would break your N-1. And the <code>crs</code> factory settings decide more than people think: <code>ha=basic</code> balances by counting machines. The five cases where we tell clients to stay.

Portal de un edificio antiguo con una única puerta acristalada, el portero automático y los buzones metálicos
8 min read

Your identity provider is not an application: it is infrastructure

On Monday 24 August, at 03:38, a denial-of-service attack began against Norway's shared government digital platform. Ten public services went down and several had nothing wrong with them: the door everyone goes through had jammed. Digdir writes on its status page that <code>eSignering</code> was unavailable "because of the limitations in ID-porten", and also that the services were "stable with the limitations that have been put in place" — part of the outage was put there by the defenders. Why single sign-on is still the right call, what changes when the door becomes infrastructure, and the three questions that reclassify it.

Cuadro eléctrico industrial abierto en una sala técnica, con embarrado de cobre, magnetotérmicos en carril DIN y cableado de potencia
8 min read

Colocation is no longer negotiated in U: it is negotiated in kW

In the first half of 2026, AI cloud providers signed 420 MW of colocation capacity in Europe. In the same period a year earlier they signed 89. Powered land in the big markets costs 82% more than in 2021. None of that raises your invoice tomorrow, which is exactly why it is worth looking at today: what changes is not the price of a rack unit, it is what your contract actually measures.

Una tormenta de verano avanzando sobre el desierto, origen del fallo de refrigeración que apagó 5.000 servidores
8 min read

Your servers can be switched off by someone you never signed anything with

On 13 August more than 5,000 servers were powered off in a building in Phoenix, taking down the websites, email and DNS of thousands of companies. The decision to shut down was the right one; what is interesting is the chain the order came down, because the end customer sits at the bottom of it with no contract with whoever decides. What to ask about the building your hardware lives in, and why DNS took down people who were not even there.

Un parquímetro con el indicador EXPIRED en rojo y un coche todavía aparcado detrás: la fecha ha pasado y no ha cambiado nada visible
9 min read

Proxmox VE 8 goes end of life in August: Debian will keep patching you, the hypervisor will not

Proxmox's official table says 2026-08 and does not give a day. What tends to fall outside the headline is that Debian 12's extended support runs to June 2028 through the usual channel, so apt will keep installing real patches on an unsupported node. What exactly freezes, how to check it, the order of the upgrade to 9.2, and why forcing it in August can be worse than being late.

Interior de un disco duro abierto: el rendimiento real de un OSD de Ceph no lo marca la ficha del fabricante sino el benchmark que midió el propio OSD
7 min read

Ceph does not perform like the datasheet: it performs like the benchmark the OSD ran at boot

Since Ceph Quincy the scheduler for BlueStore OSDs is mClock, and the work ceiling it shares out does not come from the vendor datasheet: it comes from a benchmark each OSD runs at boot. If that measurement is discarded, you are left with 315 IOPS for a spinning disk and 21,500 for a solid-state one, whatever you bought. How to check what your cluster believes, which parameters stopped having any effect, and when the drive really is the problem.

Pulsador de parada de emergencia en una pared: el nodo que se apaga a sí mismo para que el clúster pueda seguir
7 min read

Proxmox HA does not prevent downtime: it shortens it (and sometimes causes it)

Proxmox VE's own documentation sets the ceiling: about 2 minutes of error detection and failover, and no more than 99.999% availability. What really happens when a node dies (a cold start, not a live migration), why a healthy node reboots itself 60 seconds after losing quorum, the requirements everybody skips, and when we do not deploy HA at all.

Panel de salidas de una estación con horarios anunciados: el papel promete tiempos y el hierro tarda lo que tarda

Warning: Undefined array key "read_time" in /var/www/html/public/blog.php on line 2663
min read

RTO and RPO without the fluff: two numbers signed but never calculated

Almost every continuity plan carries an RPO and an RTO written with great confidence and calculated with none. What those two numbers actually promise, why your real RPO is the one of your last verified backup, the four clocks inside an RTO, and the arithmetic that dismantles a "four hours" sitting on a 1 Gbps link.

Sección de un tronco con sus anillos de crecimiento: capas acumuladas durante años, como el código del kernel donde se escondían Zapscape y SCTPhantom
8 min read

Zapscape and SCTPhantom: your Proxmox does not run Debian's kernel

Two Linux kernel flaws published this week break the two boundaries we take for granted: the virtual machine (Zapscape, CVE-2026-64561) and the container (SCTPhantom, CVE-2026-64564). Understanding them is the easy part. The hard part is answering whether the kernel your node actually boots already carries the fixes, because the versions in the advisory — 6.12.101, 7.1.6 — do not exist on your server: Proxmox does not use Debian's kernel. The exact proxmox-kernel versions that do close them (and why 7.0.14-9 is not enough), how to check in four commands, and who genuinely needs to hurry.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Proxmox VE 9.2 para arm64 anunciado el 5 de agosto de 2026: paridad de funciones con x86-64, plataformas NVIDIA Grace y Vera, y sin migración en vivo entre arquitecturas
8 min read

Proxmox on Arm doesn't extend your cluster — it makes you run two

On 5 August Proxmox shipped the first officially supported edition of Proxmox VE 9.2 for arm64: same codebase, same repositories, same lifecycle and feature parity with x86-64. Buried in the announcement there is one sentence that decides how you design your infrastructure: guests only run on nodes matching their architecture, and live migration only works between nodes of the same architecture. What they actually shipped, what you give up crossing to Arm, why the Raspberry Pi is left out, and the five questions we ask before quoting an Arm node.

Por primera vez el 46% de las cargas de IT corporativa vive en instalaciones de terceros frente al 44% en centros de datos propios, según la encuesta de Uptime Institute de 2026
11 min read

Half of corporate IT now lives off premises. That does not mean it went to the cloud

On 28 July 2026 Uptime Institute published the figure that went around the industry: for the first time, third-party facilities (46%) overtake companies' own data centres (44%). The number is real. The "the cloud won" reading is not: that 46% puts colocation and SaaS in the same box, and they are opposite decisions. And the most interesting part of the report is not in the headline but in the remaining 10%, and in what is happening to kilowatts per rack.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
7 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Caída de Google Cloud en europe-west4-a por fallo de energía y refrigeración en el datacenter
10 min read

Three milliseconds and 44 degrees: the cloud outage that had nothing to do with software

On 15 July 2026 a three-millisecond voltage dip on the utility feed took three services in a Google Cloud zone in the Netherlands out of service for almost fifteen hours. No CVE, no botched deployment, no BGP route: an electrical transient, a backup system that failed to pick up the load, a chiller controller that dropped offline, and a data hall at 44°C. What exactly failed according to the official incident report, why redundancy on paper is not always redundancy, what it means that a zone is not a building, and the seven questions worth asking any datacenter — including your own — before it happens.

VMSA-2026-0006: dos vulnerabilidades CVSS 9,8 en VMware vCenter y un escape de máquina virtual en ESX
8 min read

Two 9.8s in vCenter, a VM escape and the flaw nobody will look at

On 29 July 2026 Broadcom published VMSA-2026-0006: five flaws in VMware ESX, vCenter, Workstation and Fusion, two of them CVSS 9.8 in vCenter and one 9.3 that allows escaping from a virtual machine to the host. There are no workarounds. What to patch first according to the advisory itself (the order is no longer the one you knew), why updating vCenter does not stop your workloads, where the patches are if you hold a perpetual licence with no support, and why the lowest-scoring flaw — ESX may not record what an administrator does — is the one that hurts afterwards.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN