Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Actualizar Ceph de Squid a Tentacle en Proxmox: la ventana en la que el clúster corre en dos versiones
9 min read

Ceph to Tentacle: during the upgrade your cluster runs two versions at once

Squid expires on 31 October and Tentacle has been in Proxmox's enterprise repository since July, so the maintenance window is no longer hypothetical. Inside it something happens that almost no plan accounts for: monitors, managers and OSDs restart separately, and the cluster spends hours — or days — split across two versions. Why "restart OSDs on one node at a time" decides your window, why calling noout "optional" is misleading, and the command most people mistake for the finish line.

Servidores de rack idénticos apilados en un carro metálico, pendientes de montar, delante de un rack a medio poblar
8 min read

Corosync adds 650 milliseconds per node: the clock your upgraded cluster is still carrying

The time a Proxmox cluster takes to re-form membership after losing a node is not fixed: it grows by 650 ms for every node you add, and on factory values a 29-node cluster reaches 45.21 seconds — exactly where the documentation itself asks you to fix it, before the 60-second watchdog starts rebooting healthy nodes. Proxmox VE 9.2 lowered it to 125 ms, but only when the cluster is created: clusters upgraded from 8 to 9 keep the old value.

Servidor de almacenamiento abierto en un rack con las bahías de discos a la vista y una unidad extraída de su carro
9 min read

In Ceph, capacity is not set by the cluster: it is set by the fullest disk

A single OSD above 95% stops writes across the whole cluster even while "ceph df" still shows dozens of free terabytes. The three default thresholds (0.85 / 0.90 / 0.95), why the mechanism that repairs switches off five points before the one that serves, and the capacity calculation with one node missing that almost nobody runs: with four nodes the ceiling is 71 points, and 67 if you want the rebuild to actually finish.

Chasis de servidor de almacenamiento extraído sobre sus guías en un pasillo de datacenter, con dos filas de discos de 3,5 pulgadas en bandejas metálicas y un destornillador apoyado en el borde
7 min read

Ceph patches four CVEs: the package closes three, the fourth is on you

On 19 August Ceph shipped Squid 19.2.6 and Tentacle 20.2.4 tagged [URGENT]. One of the four flaws is not fixed by installing anything: it forces you to rotate every CephX key in the cluster, ten manual steps, and it leaves the cluster in HEALTH_ERR in the meantime. What is inside each CVE, why anyone holding a "mon allow r" key could read your OSD LUKS passphrases, and what we found today in Proxmox's Ceph repository.

Un parquímetro con el indicador EXPIRED en rojo y un coche todavía aparcado detrás: la fecha ha pasado y no ha cambiado nada visible
9 min read

Proxmox VE 8 goes end of life in August: Debian will keep patching you, the hypervisor will not

Proxmox's official table says 2026-08 and does not give a day. What tends to fall outside the headline is that Debian 12's extended support runs to June 2028 through the usual channel, so apt will keep installing real patches on an unsupported node. What exactly freezes, how to check it, the order of the upgrade to 9.2, and why forcing it in August can be worse than being late.

Interior de un disco duro abierto: el rendimiento real de un OSD de Ceph no lo marca la ficha del fabricante sino el benchmark que midió el propio OSD
7 min read

Ceph does not perform like the datasheet: it performs like the benchmark the OSD ran at boot

Since Ceph Quincy the scheduler for BlueStore OSDs is mClock, and the work ceiling it shares out does not come from the vendor datasheet: it comes from a benchmark each OSD runs at boot. If that measurement is discarded, you are left with 315 IOPS for a spinning disk and 21,500 for a solid-state one, whatever you bought. How to check what your cluster believes, which parameters stopped having any effect, and when the drive really is the problem.

Parte trasera de un rack de nodos de almacenamiento: la mejora de Fast EC se enciende pool por pool, no con la actualización
7 min read

Fast EC ships switched off: the Ceph Tentacle flag that only turns once

Ceph Tentacle ships Fast EC, the erasure coding performance work people had been waiting years for. And it arrives switched off: you enable it pool by pool, with one command, and the monitor then refuses to clear it — rolling back means draining and recreating the pool. On top of that, the "at least double" in the headline was measured with a 16K stripe unit, which is precisely what an existing pool cannot have. The conditions the monitor enforces, the half of the improvement frozen on the day you created the pool, what happens to the cluster when you flip it, and why three-way replication is still faster.

Ceph Squid 19.2 llega a su fin de vida estimado el 19 de septiembre de 2026
7 min read

Your Ceph has a date: Squid runs out of patches on 19 September

Ceph's lifecycle table puts the estimated end of life of Squid (19.2) on 19 September 2026: fifty days from today. Its replacement, Tentacle (20.2), has been stable since November and Proxmox has marked it stable since 9.2. The problem is not the jump, it is that it is not a jump: it is a sequence of three maintenance windows whose order you do not get to choose, with two details almost nobody has looked at — the mgr/zabbix module is gone, and erasure coding optimisations do not switch themselves on.

Proxmox VE 8 llega a su fin de soporte en agosto de 2026
8 min read

Proxmox VE 8 runs out of patches in August: why we won't upgrade on the 30th

The lifecycle table in Proxmox's official documentation puts the end of life of the 8 branch in August 2026. Just over thirty days are left, and the typical reaction is to block out a weekend and jump to 9. Our stance is the opposite: there are six situations where upgrading this August is a worse idea than being late. The live-migration asymmetry that turns your rollback into a restore, why Ceph means two windows and not one, the containers with old systemd that will not start, and a realistic split of the thirty days left.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN