Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Pasillo de un centro de datos con un rack abierto a medio poblar y un carro elevador con un servidor encima
5 min read

When NOT to migrate from VMware to Proxmox

Migrating from VMware to Proxmox is part of what we do, and there are cases where our answer is: not now. Two classic objections no longer hold — the scheduler's dynamic mode arrived with Proxmox VE 9.2 on 21 May, and Veeam 13.1 has shipped replication since 29 July. The one still standing is different: Proxmox's HA documentation describes nothing equivalent to vSphere's <em>admission control</em>, which flatly refuses to power on the machine that would break your N-1. And the <code>crs</code> factory settings decide more than people think: <code>ha=basic</code> balances by counting machines. The five cases where we tell clients to stay.

Rack abierto en una sala de servidores con dos bandejas de disco a medio sacar
5 min read

10% of the VMDK is enough: the arithmetic that changes your recovery plan

The ESXi encryptor Rapid7 took apart carries a percentage parameter, and the value observed was 10: on a large VMDK it touches only a tenth of the file, and that is enough to stop it booting. Partial encryption is not new — LockFile was doing it in 2021 — but the numbers are. What it does to your response clock, why no EDR agent belongs on the hypervisor (Broadcom says in so many words that it is not supported), what the same actor does to backup services, and why swapping hypervisors is not a security control.

Servidor de almacenamiento de 4U extraído sobre sus guías en una sala de servidores, con la tapa quitada y las filas de discos a la vista
9 min read

Proxmox's "protected" flag is not a lock, it's a latch

The Pay2Key ransomware shuts down the guests on a Proxmox cluster and deletes the backups using Proxmox's own API: first a <code>--protected 0</code>, then the delete. We read the pve-storage source to see why it works, and the answer is uncomfortable: clearing the latch never costs one privilege more than deleting the backup. What does raise a real boundary, and why it costs nothing.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Un parquímetro con el indicador EXPIRED en rojo y un coche todavía aparcado detrás: la fecha ha pasado y no ha cambiado nada visible
9 min read

Proxmox VE 8 goes end of life in August: Debian will keep patching you, the hypervisor will not

Proxmox's official table says 2026-08 and does not give a day. What tends to fall outside the headline is that Debian 12's extended support runs to June 2028 through the usual channel, so apt will keep installing real patches on an unsupported node. What exactly freezes, how to check it, the order of the upgrade to 9.2, and why forcing it in August can be worse than being late.

Interior de un disco duro abierto: el rendimiento real de un OSD de Ceph no lo marca la ficha del fabricante sino el benchmark que midió el propio OSD
7 min read

Ceph does not perform like the datasheet: it performs like the benchmark the OSD ran at boot

Since Ceph Quincy the scheduler for BlueStore OSDs is mClock, and the work ceiling it shares out does not come from the vendor datasheet: it comes from a benchmark each OSD runs at boot. If that measurement is discarded, you are left with 315 IOPS for a spinning disk and 21,500 for a solid-state one, whatever you bought. How to check what your cluster believes, which parameters stopped having any effect, and when the drive really is the problem.

Pulsador de parada de emergencia en una pared: el nodo que se apaga a sí mismo para que el clúster pueda seguir
7 min read

Proxmox HA does not prevent downtime: it shortens it (and sometimes causes it)

Proxmox VE's own documentation sets the ceiling: about 2 minutes of error detection and failover, and no more than 99.999% availability. What really happens when a node dies (a cold start, not a live migration), why a healthy node reboots itself 60 seconds after losing quorum, the requirements everybody skips, and when we do not deploy HA at all.

Sala llena de ordenadores encendidos y funcionando con normalidad: los certificados de Secure Boot caducaron en junio y ningún equipo dejó de arrancar
7 min read

Secure Boot expired in June and nothing broke. That is the problem

On 24 and 27 June, two of the certificates Microsoft has used to sign the boot chain since 2011 expired. Not a single machine went down: Microsoft states plainly that the device keeps starting and updating normally. What stops is something else — revocations, the boot manager, early-boot mitigations — and it raises no alert at all. A third date is still open: 19 October. How to check in two minutes whether your Windows estate, your Linux servers and — this is the one nobody looks at — your virtual machines already carry the 2023 certificates.

Sección de un tronco con sus anillos de crecimiento: capas acumuladas durante años, como el código del kernel donde se escondían Zapscape y SCTPhantom
5 min read

Zapscape and SCTPhantom: your Proxmox does not run Debian's kernel

Two Linux kernel flaws published this week break the two boundaries we take for granted: the virtual machine (Zapscape, CVE-2026-64561) and the container (SCTPhantom, CVE-2026-64564). Understanding them is the easy part. The hard part is answering whether the kernel your node actually boots already carries the fixes, because the versions in the advisory — 6.12.101, 7.1.6 — do not exist on your server: Proxmox does not use Debian's kernel. The exact proxmox-kernel versions that do close them (and why 7.0.14-9 is not enough), how to check in four commands, and who genuinely needs to hurry.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Proxmox VE 9.2 para arm64 anunciado el 5 de agosto de 2026: paridad de funciones con x86-64, plataformas NVIDIA Grace y Vera, y sin migración en vivo entre arquitecturas
5 min read

Proxmox on Arm doesn't extend your cluster — it makes you run two

On 5 August Proxmox shipped the first officially supported edition of Proxmox VE 9.2 for arm64: same codebase, same repositories, same lifecycle and feature parity with x86-64. Buried in the announcement there is one sentence that decides how you design your infrastructure: guests only run on nodes matching their architecture, and live migration only works between nodes of the same architecture. What they actually shipped, what you give up crossing to Arm, why the Raspberry Pi is left out, and the five questions we ask before quoting an Arm node.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
7 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Proxmox VE 8 llega a su fin de soporte en agosto de 2026
5 min read

Proxmox VE 8 runs out of patches in August: why we won't upgrade on the 30th

The lifecycle table in Proxmox's official documentation puts the end of life of the 8 branch in August 2026. Just over thirty days are left, and the typical reaction is to block out a weekend and jump to 9. Our stance is the opposite: there are six situations where upgrading this August is a worse idea than being late. The live-migration asymmetry that turns your rollback into a restore, why Ceph means two windows and not one, the containers with old systemd that will not start, and a realistic split of the thirty days left.

Proxmox VE entra en el ecosistema de NVIDIA Mission Control: qué cambia de verdad para tu infraestructura
7 min read

Proxmox joins NVIDIA's ecosystem: a logo will not migrate your infrastructure

Today Proxmox Server Solutions announced it is joining the NVIDIA Mission Control ecosystem: Proxmox VE as the virtualisation and high-availability layer beneath the management services of AI factories, with engineering work for the Grace and Vera CPUs. What the announcement actually says, where Proxmox sits in that picture and where it does not, and why an announcement changes the conversation in a boardroom but changes none of the things that decide your migration.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN