Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de servidores con racks cableados y un módulo de gestión de potencia
9 min read

Moving to Proxmox 9.2 wasn't your call: the repository made it

Ask whoever runs your cluster who decided to go from 9.1 to 9.2, and in which meeting it was approved. In most places nobody decided: Proxmox VE ships no repository per minor version —there is nothing like a pve-9.1-security— so a routine apt dist-upgrade, the same one applying the patches you do want, leaves you on the latest published minor. The software that takes your backups does have a supported-version matrix, and it runs behind: Proxmox VE 9.2 shipped on 21 May 2026 and the Veeam plug-in covering it arrived on 29 July, 69 days later. And one detail misleads: plug-in 3.3 for the 13.0 branch shipped on 25 August, twenty-seven days AFTER 4.0, so "I am up to date" can mean up to date on the branch that does not carry the new support. Nothing turns red; what you lose is the right to open a case. The three facts that must live on the same line before you open the window, why the right order is matrix first and apt second, the ARM architecture boundary, and where this crack does not exist.

Técnico agachado detrás de un rack, con el portátil apoyado en el suelo técnico y un manojo de cables sueltos al lado
10 min read

Moving to Proxmox doesn't touch your licences; failover does

The Windows licensing question comes up in every migration meeting, and the short answer disappoints everyone: changing hypervisor recalculates nothing. Something else changes the bill, and Microsoft has it written in a single sentence: "License Mobility across Server Farms is not available for Windows Server, so each server must be licensed for peak capacity at all times." Each server, peak capacity, at all times. The licence does not follow the virtual machine, so the number depends on how many nodes it could ever start on: 32 core licences or 96, for exactly the same installation. What changed in SQL Server 2022, why the AVMA myth does not apply to you if you are coming from vSphere, and why a Proxmox affinity rule is a useful control but not a contractual boundary.

Nodos idénticos apilados en un rack, cada uno con su pantalla y su etiqueta
9 min read

Your three-node Ceph does not heal itself: it holds on

A dead disk in a three-node cluster fixes itself provided another disk remains on that same server: the CRUSH rule descends to another OSD on the same host. A dead HOST does not. With replica 3 and the failure domain set to "host" — what Proxmox ships by default — there is no fourth place to put the third copy, so placement groups sit at active+undersized+degraded until the node comes back. And the cluster keeps serving, which is exactly why nobody looks at it. Ceph's real timers (20 seconds, 10 minutes, 15 minutes), what you cannot touch while the degraded window lasts, why recovery can cost you corosync quorum, and why the number that matters is not how many nodes you have but how many distinct places.

Armario de servidores con cada máquina etiquetada a mano, una por una
8 min read

Your Proxmox backup skips disks and the job still turns green

The limitations page for the Veeam plug-in for Proxmox VE was updated on 15 September 2026, and two lines in it carry the word that really matters: skipped. There are two very different kinds of "not supported": the one that stops your job and the one that skips a disk and paints the job green. What falls outside the backup of a Proxmox platform, what does not come back when the machine comes back, why LXC containers are a separate inventory, and why the backup manual gets read before you choose your storage rather than on restore day.

Frontal de varios servidores de rack apilados, con sus bandejas de disco etiquetadas y los pilotos de estado encendidos
9 min read

Piloting a VMware alternative is not migrating

Gartner has put a number on leaving VMware, and the number will be misquoted all autumn: by 2029, 55% of enterprises "will initiate proofs of concept" for alternatives, up from 25% in 2026. Initiate pilots, not migrate. Our argument is that most of those pilots will not help anyone decide anything, because they are built to succeed: install it, boot a VM, close the meeting. The six things an honest pilot has to try to break — starting with the restore, not the migration — the variable no analyst can give you (your renewal date), and the cases where we still tell people to stay.

Pasillo frío de un centro de datos con una silla vacía y un carro de consola aparcado junto a un armario abierto
7 min read

The Proxmox CVE your scanner cannot evaluate

CVE-2023-54391 is a 9.8: you get in as root@pam with no password. We queried its record through the NVD API and the GitHub Advisories API, and here is what comes back: NVD publishes no CPE configuration at all and flags the record as Deferred; GitHub returns an empty list of affected packages; and the only range that exists stops at "7.4" while your nodes call themselves 7.4-17. A scanner that decides by version matching has nothing to decide with. Meanwhile a provider published its post mortem: twelve hypervisors mining from 31 August to 17 September, logs wiped and the sentence "we cannot prove it".

Interior de un servidor de dos zócalos abierto, con los procesadores y dos bancos de módulos de memoria a la vista
11 min read

Patching the kernel means rebooting, and the reboot erases the evidence

CISA added two Linux kernel flaws to its exploited catalogue today, due by Monday. One has sat in your scanner for eleven months rated 3.3 out of 10; the kernel project scores it 7.8 on the very same record. Both entries carry the forensic-triage flag CISA now attaches to two out of every three new additions, and its guidance says not to remediate before collecting evidence. In the kernel, remediating means rebooting. And rebooting erases a good part of what you are asked to keep.

Cabina de disco montada en rack, con dos filas de bandejas de disco y sus pilotos de actividad
10 min read

Moving to Proxmox and reusing your SAN: the snapshot is what does not travel

The array is paid for, so it stays: the cheapest-looking decision in the project and the one that changes your day-to-day the most. In Proxmox the snapshot is not taken by the hypervisor but by the storage plugin, and on a shared LUN with LVM-thick the documentation says «snapshots are not possible by default…». What fixes that has been labelled a technology preview since 9.0, and the vendor puts it in writing on its own roadmap. The seven real options and the decision tree we are willing to sign.

Varios servidores de 1U apilados en un rack, con cableado de red blanco recogido y pantallas LCD de estado en el frontal
10 min read

Ceph changes cipher: rebooting the virtual machine does not refresh the key

On 9 September Proxmox published the procedure to migrate cephx keys from aes to aes256k. The hard part is not cryptographic: it is knowing what counts as "refreshing a client". The documentation says it in six words — "A guest reboot is not enough" — and the failure does not show up when you run the command, but minutes or days later, when a ticket expires. What has changed since August, the kernel 7.0 gate, and the order we follow.

Pasillo de un centro de datos con dos filas de armarios de rack idénticos
9 min read

The cluster picks a node by counting guests: anti-affinity in Proxmox VE 9 and the rule nobody declares

When a node goes down, the Proxmox VE scheduler decides where your HA-managed machines come back up. On a freshly installed cluster it does that by counting active guests: it has no idea that 101 is the second leg of 100. Proxmox VE 9.0 brought affinity rules so you can tell it, with an asymmetry worth knowing — the rule that pins a guest to a node is a preference, the rule that keeps two guests apart is an order — and an arithmetic that decides whether your VM comes back degraded or does not come back at all.

Parte trasera de una librería de cintas con las unidades LTO y su cableado de fibra
5 min read

Broadcom pulls the VDDK: the first thing that breaks is not your migration, it is your backup

In late August the download pages for the Virtual Disk Development Kit started returning a 404, with no announcement and no deprecation notice. The coverage has read it as "leaving VMware just got harder", and that is half true: it depends where you are going, because Proxmox VE's ESXi importer does not even use it. What almost nobody has looked at is Broadcom's exact wording — "no longer available for use or download" — or the place where that library has been working for twenty years without anyone looking at it: inside your backup.

Armarios de rack vacíos recién instalados en el pasillo de una oficina
9 min read

VMware to Proxmox: the disk arrives intact, Windows will not boot, and the mistake was made two weeks earlier

The Proxmox VE import wizard copies the machine off ESXi without a hitch. Then Windows will not boot, and it is not the wizard's fault: the official documentation says that to boot from VirtIO SCSI, Windows "needs to see a disk requiring the driver before". That before is the problem, because the only place you can do it is the machine you have already shut down. The official way out works, but it is a per-machine, sequential procedure that lives inside the maintenance window. The alternative is not to speed it up: it is to move it to another date.

Filas de bandejas de disco SAS en el frontal de varios servidores de almacenamiento montados en rack
9 min read

Squid gained 42 days and Tentacle lost 170: a single commit moved Ceph's end of life

On 5 August, a commit in the Ceph documentation moved the two dates that govern the calendar of anyone running distributed storage in production: Squid went from 19 September to 31 October, and Tentacle from 18 November 2027 to 1 June 2027. The extension is visible in the chart; the 170-day cut to the version everyone is migrating to we have not seen discussed anywhere. What it means that the field is called target_eol, and why Tentacle lives 560 days where Squid lived 765.

Sala de servidores de empresa de noche, con las luces apagadas, la puerta entreabierta a un pasillo iluminado, un taburete vacío junto al rack y un carro de servicio aparcado en el pasillo
5 min read

Proxmox goes 24/7 on 19 October: what those two hours actually buy you

On 2 September 2026 Proxmox announced that its enterprise support goes 24/7 on 19 October, and opened a North American subsidiary. Until now it ran Monday to Friday, 07:00–17:00 CET/CEST, on Austrian business days. What each plan includes, what it really costs per CPU socket, the three asymmetries sitting inside the announcement itself —response is not resolution, local support stays office hours, and the scope is three products rather than your system— and the six questions for reading any 24/7 support contract, your provider's included.

Omnissa Horizon certificado en Proxmox VE: dos puestos de oficina vacíos con los monitores apagados y un cliente ligero detrás de la pantalla
9 min read

Proxmox VE is now Horizon Ready, but in manual mode: you create and power off the desktops yourself

On 4 September 2026 Proxmox announced that Proxmox VE has achieved Omnissa Horizon Ready Hypervisor certification. It is real and it removes a requirement, but it lands in "Manual Provisioning Mode": the program page states that provisioning and power policy are not supported. Meanwhile, Horizon has been integrating over the API with another non-vSphere hypervisor since December. Two different regimes, what Horizon stops doing for you, the RAM and GPU arithmetic nobody runs, and which estates this is a way out for today.

Proxmox VE 7 y CVE-2023-54391: dos servidores viejos todavía encendidos en la estantería de un cuarto trastero
7 min read

Proxmox VE 7: the patch had been out for three years and nobody knew it was a patch

On 1 September 2026 Proxmox published advisory PSA-2026-00043-1: on Proxmox VE 7, sending any tfa-challenge value is enough to log in as root@pam with no password. The code that fixed it shipped on 20 July 2023 inside a refactor nobody classified as security, which is why it was never backported. What the flaw does, why a second factor saved you, what to check on your node today, and what all of this says about your inventory.

Actualizar Ceph de Squid a Tentacle en Proxmox: la ventana en la que el clúster corre en dos versiones
9 min read

Ceph to Tentacle: during the upgrade your cluster runs two versions at once

Squid expires on 31 October and Tentacle has been in Proxmox's enterprise repository since July, so the maintenance window is no longer hypothetical. Inside it something happens that almost no plan accounts for: monitors, managers and OSDs restart separately, and the cluster spends hours — or days — split across two versions. Why "restart OSDs on one node at a time" decides your window, why calling noout "optional" is misleading, and the command most people mistake for the finish line.

Parte trasera de un rack abierto con servidores apilados y cables de red recogidos con bridas
11 min read

Migrating to Proxmox: the network is not held by the cluster, it is held by each node

In a VMware to Proxmox migration everybody watches the disks. Disks are the easy part: they either arrive or they do not, and you find out straight away. What gets left out of the luggage is the network configuration: in Proxmox VE it lives in a file on each node, outside the filesystem the cluster replicates. We go through the documentation sentence that says so, why the bridge is missing from the official list of live migration requirements, what the MAC change drags with it, the 10.0.2.x symptom that wastes hours, and how far SDN really takes you.

Servidores de rack idénticos apilados en un carro metálico, pendientes de montar, delante de un rack a medio poblar
5 min read

Corosync adds 650 milliseconds per node: the clock your upgraded cluster is still carrying

The time a Proxmox cluster takes to re-form membership after losing a node is not fixed: it grows by 650 ms for every node you add, and on factory values a 29-node cluster reaches 45.21 seconds — exactly where the documentation itself asks you to fix it, before the 60-second watchdog starts rebooting healthy nodes. Proxmox VE 9.2 lowered it to 125 ms, but only when the cluster is created: clusters upgraded from 8 to 9 keep the old value.

Servidor de almacenamiento abierto en un rack con las bahías de discos a la vista y una unidad extraída de su carro
9 min read

In Ceph, capacity is not set by the cluster: it is set by the fullest disk

A single OSD above 95% stops writes across the whole cluster even while "ceph df" still shows dozens of free terabytes. The three default thresholds (0.85 / 0.90 / 0.95), why the mechanism that repairs switches off five points before the one that serves, and the capacity calculation with one node missing that almost nobody runs: with four nodes the ceiling is 71 points, and 67 if you want the rebuild to actually finish.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN