Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Actualizar Ceph de Squid a Tentacle en Proxmox: la ventana en la que el clúster corre en dos versiones
9 min read

Ceph to Tentacle: during the upgrade your cluster runs two versions at once

Squid expires on 31 October and Tentacle has been in Proxmox's enterprise repository since July, so the maintenance window is no longer hypothetical. Inside it something happens that almost no plan accounts for: monitors, managers and OSDs restart separately, and the cluster spends hours — or days — split across two versions. Why "restart OSDs on one node at a time" decides your window, why calling noout "optional" is misleading, and the command most people mistake for the finish line.

Servidor de almacenamiento abierto en un rack con las bahías de discos a la vista y una unidad extraída de su carro
9 min read

In Ceph, capacity is not set by the cluster: it is set by the fullest disk

A single OSD above 95% stops writes across the whole cluster even while "ceph df" still shows dozens of free terabytes. The three default thresholds (0.85 / 0.90 / 0.95), why the mechanism that repairs switches off five points before the one that serves, and the capacity calculation with one node missing that almost nobody runs: with four nodes the ceiling is 71 points, and 67 if you want the rebuild to actually finish.

Armario de llaves metálico abierto en el pasillo de servicio de una oficina, con dos hileras de llaves colgadas de sus ganchos
7 min read

They deleted the backups at both data centres

Joint advisory AA26-222A, published on 10 August 2026 by six agencies, records that at one Gunra victim the actors deleted backup and archived data at the primary data centre <em>and</em> at the recovery one, before and after deploying the encryptor. Another section describes how they got the key cabinet: SSH to an access control server and a symmetric key that decrypted the passwords for enterprise server accounts across the company. Our reading: two sites that accept the same credential are one site with two postal addresses. What falls outside a retention lock, and six checks for this week — two of which have to be actually run.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Interior de un disco duro abierto: el rendimiento real de un OSD de Ceph no lo marca la ficha del fabricante sino el benchmark que midió el propio OSD
7 min read

Ceph does not perform like the datasheet: it performs like the benchmark the OSD ran at boot

Since Ceph Quincy the scheduler for BlueStore OSDs is mClock, and the work ceiling it shares out does not come from the vendor datasheet: it comes from a benchmark each OSD runs at boot. If that measurement is discarded, you are left with 315 IOPS for a spinning disk and 21,500 for a solid-state one, whatever you bought. How to check what your cluster believes, which parameters stopped having any effect, and when the drive really is the problem.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
7 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Subida del precio de la memoria DRAM y NAND en 2026 por la demanda de centros de datos de IA
8 min read

AI took the RAM: what to do with your 2026 hardware plan

TrendForce forecast second-quarter contract price rises of 58% to 63% for conventional DRAM and 70% to 75% for NAND. In one quarter, with nothing inside your company to explain it. Why the big cloud providers are hedged by multi-year contracts and you are not, how this lands in your refresh plan, what to check before signing a purchase order, and how long it lasts — with dates.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN