Important notes
The Oxide CLI, Go SDK, and Terraform Provider have been updated for API enhancements described under New features.
The support bundle API endpoints have moved out of the experimental namespace. The
/paths are replaced byexperimental/ v1/ system/ support-bundles /. See the Troubleshooting guide for more details on generating support bundles. (omicron#11097)v1/ system/ support-bundles The
discoverablefield has been removed from thesilo_createAPI endpoint. Requests from older clients that include the field are accepted and the silo will be created asdiscoverable. (omicron#11296)
System requirements
Please refer to v1.0.0 release notes.
Installation
Oxide Computer Model 0 must be installed and configured under the guidance of Oxide technicians. The requirement may change in future releases.
Upgrade compatibility
Upgrade from version 22 is supported. Existing instances will
continue to run until the sled they run on is restarted, at which point
they will be transitioned to the failed state. Instances with an
auto-restart policy
set to never will remain in the failed state until started
manually. Any instances that are sensitive to hard shutdowns should be
gracefully shut down from within the guest operating system before the
update commences.
All existing setup and data (e.g., projects, users, instances) remain intact after the software update. More details can be found on the system update page.
New features
IPv6-only rack networking
The rack can now be set up with IPv6-only external networking. Control plane services with external addresses (external DNS, boundary NTP, and the API and web console) are assigned addresses from an IPv6 service IP pool. See the Network Preparations guide for an example configuration. (omicron#11208, omicron#11207, omicron#11092, omicron#11236)
Alert listing
Alerts can be listed and viewed directly with the alert_list and
alert_view API endpoints without first creating an alert receiver. See
Viewing alerts in the Alerts
guide for more details.
(omicron#11072)
Optional default resources on project and VPC creation
The project_create and vpc_create API endpoints accept an optional
defaults field, which controls whether the default VPC and default subnet are
created.
(omicron#9750)
Sled slot in hardware inventory
The sled_list and sled_view API responses now include the sled’s slot
number in the rack.
(omicron#11077)
Web console
There are three new pages for operators under System: audit log, alerting with webhooks, and support bundles.
Silo quotas can now be edited from the system utilization page.
Number fields show an error for out-of-range values rather than attempting to set them.
The console is more usable on small screens, and screen readers now announce page changes and read button tooltips.
Full console changelog
Audit log page for operators (console#2860)
Alerting page: manage webhook receivers, send test alerts, and view delivery history (console#3320)
Support bundles page: create, list, and download support bundles (console#3311)
Edit silo quotas directly from the system utilization page (console#3330)
Usable layout on phone-sized screens (console#3358)
Number fields show an error for out-of-range or fractional values instead of rewriting them to the nearest bound (console#3282, console#3373, console#3376, console#3377)
Instance size presets use 1 vCPU per 8 GiB of memory; high-CPU and high-memory presets removed (console#3384)
Silo create warns when a TLS certificate doesn’t match the silo domain or has expired (console#2582)
Side panels show resource metadata such as ID and creation time (console#3302)
Truncated text fills available width instead of cutting at a fixed character count (console#3325, console#3293)
Metrics charts pick rounder axis ticks, and the y-axis scales to fit small values (console#3295)
More accurate IPv6 address and prefix validation (console#3334, console#3343)
Screen readers announce route changes and read button tooltips (console#3332, console#3333)
Many other small UI fixes (console#3392, console#3371, console#3366, console#3364, console#3360, console#3346, console#3345, console#3344, console#3342, console#3337, console#3336, console#3319, console#3013)
Other enhancements and bug fixes
Old blueprints are pruned automatically (omicron#10309)
Instances are not placed on sleds being evacuated for update (omicron#11173, omicron#11293)
System update no longer shows a spurious "contact support" warning before the first blueprint exists (omicron#11157)
Nexus no longer polls VMMs that are terminal or belong to deleted instances (omicron#11100)
SAML responses are checked against the XML signature rules in section 5.4 of the SAML core specification (omicron#11322)
SAML identity provider metadata is fetched with the same external HTTP client configuration as other outbound requests (omicron#11320)
Failed alert deliveries are resent even when the same alert was delivered successfully to another receiver (omicron#11318)
OPTE periodically sends unsolicited IPv6 router advertisements, so service zones on an IPv6-only rack recover their default route without intervention (opte#1054, omicron#11313) (dendrite#356)
Release artifact size is reduced by about 25% (omicron#10887)
Known behavior and limitations
End-user features
| Feature Area | Known Issue/Limitation | Issue Number |
|---|---|---|
Disk/image management | Disks in | |
Disk/image management | Disk rejected by guest OS due to duplicate nvme device names. The issue is caused by a 20-character limit in applying the disk name to the device serial number. See the Troubleshooting guide for more information. | - |
Disk/image management | The ability to modify image metadata is not available at this time. | |
Instance networking | Instances can become inaccessible on a sled that loses communication with switches; a reboot is currently required to restore access. | - |
Instance orchestration | Unable to start an instance that has a disk replica on a sled being updated. | |
Instance orchestration | Instance start API frequently times out when attached to local disks. | |
Instance orchestration | New instances cannot be created when the total number of NAT entries (private-to-external IP mappings) in the system exceeds 1024. | |
Instance performance | The | |
Instance performance | Linux guests unable to capture hardware events using | |
VPC internet gateway | Changing a silo’s default IP pool causes some instances to lose their outbound internet access. This is due to a mismatch between the pool containing the instances' external IP (which are allocated from the new default pool) and the pool attached to the system-created internet gateways (which are linked to the old pool during creation time). Please see the Troubleshooting guide for some possible options for restoring instance outbound connectivity. | |
VPC internet gateway | An internet gateway cannot have both an IPv4 and an IPv6 address attached. | |
VPC routing | Subnet update clears custom router ID when the field is left out of the request body. | |
VPC routing | Network interface update clears transit ips when the field is left out of the request body. | - |
Telemetry | VM instance memory utilization and VPC network/firewall metrics are unavailable at this time. | - |
Operator features
| Feature Area | Known Issue/Limitation | Issue Number |
|---|---|---|
Rack setup | On an IPv6-only rack, boundary NTP zones can lose their default route after a full rack reboot. The route is restored automatically, but time synchronization can take up to 10 minutes. | |
Reliability | Sled memory usage improvement required to prevent system services from restarting when under extreme memory pressure. | - |
Silo management | The ability to modify silo and IDP metadata is not available at this time. | |
System management | Real-time availability status for sleds and physical storage is not yet shown in the inventory API or UI. | |
System management | Operator-driven instance migration across sleds is currently unavailable. | - |
System management | Some running instances transitioned to the "stopped" state after update. |