LXD 6.10.0 release notes¶
This is a LTS release and is recommended for production use.
This is the first LTS release for the 6 series. It consolidates new features, storage and networking advancements, disaster recovery capabilities, security hardening, and bug fixes from across the 6 series.
Note
Release notes content These release notes cover updates in the core LXD repository and the LXD snap package. For a tour of LXD UI updates, please see the release announcement in our Discourse forum.
Highlights¶
This section highlights new and improved features in this release.
Image registries¶
Image registries provide a unified view of image sources available to a LXD cluster. Clients now specify an image registry when requesting the LXD daemon to download an image.
Projects can restrict image downloads to specific authorized image registries using the new restricted.registries project configuration key.
This allows an administrator to specify the image sources that tenants can access.
Image registries support using another LXD cluster as an image source by referencing a cluster link. Simple Streams image servers are also supported.
Client-side image remotes remain supported, but clients should specify an image registry rather than a URL and protocol when requesting an image download. A comprehensive compatibility layer was added to support older LXD clients with the transition.
Documentation: Image registries and How to manage image registries
API extension: image_registries
Persistent changed block tracking for VM block volumes¶
Warning
Changed block tracking is a feature preview and must not be enabled in a production environment. See Configure feature previews for more details.
Virtual machine block volumes now support persistent changed block tracking (CBT).
LXD leverages QEMU dirty bitmaps and NBD export interfaces to track disk blocks modified between snapshots. External backup tools and migration pipelines can query and download only the altered blocks rather than whole disk images, significantly reducing backup windows, bandwidth usage, and storage overhead.
Documentation: How to track changed blocks on virtual machine volumes
API extension: storage_volume_block_tracking
Ceph RBD mirroring for project volume replication¶
Disaster recovery replicators now support asynchronous Ceph RBD storage mirroring.
When replicating a project’s instances and exclusively attached volumes using Ceph RBD storage pools, LXD coordinates with Ceph’s native volume mirroring capabilities instead of performing userspace block transfers. Standby clusters receive mirrored image updates natively, and LXD manages all volume promotion, demotion, and leader failover operations.
Documentation: Replicators
API extension: storage_ceph_replicator
Custom volume support in replicators¶
Disaster recovery replication now supports custom storage volumes with the introduction of the all-exclusive disk volumes mode for instance migration.
When migrating or replicating instances, any custom storage volumes attached exclusively to the instance, along with their volume snapshots, are automatically transferred in the same operation. Volumes attached to multiple instances or shared across the project are not replicated.
Documentation: Replicators
API extension: replicator_custom_volumes
Disaster recovery and replicator metrics¶
Dedicated Prometheus metrics and recovery point objective (RPO) tracking have been added for disaster recovery replicators.
LXD now exposes gauges for lxd_replicators, lxd_replicator_last_run_status, lxd_replicator_last_success_timestamp, and lxd_replicator_last_success_oldest_snapshot_timestamp.
These metrics provide real-time visibility into replication health and the age of the oldest replicated snapshot.
Documentation: Provided metrics
API extension: metrics_replicators
Unidirectional cluster links¶
The cluster links API now supports unidirectional relationships.
A local cluster can establish an authenticated link to a remote cluster by consuming an authorization trust token issued by the remote cluster. The remote cluster validates and authenticates incoming requests from the local cluster while preventing outbound connections back to the local cluster, accommodating network topologies with strict firewall or one-way ingress rules.
Documentation: Cluster links
API extension: cluster_links_unidirectional
Public cluster links¶
Cluster links can now connect to public or read-only remote clusters without client certificate authentication.
Public cluster links verify the remote endpoint using TLS certificate fingerprint pinning during a two-phase creation workflow. This enables access to public services and image registries without creating reciprocal identities or exchanging mutual credentials.
Documentation: Cluster links
API extension: cluster_links_public
OVN load balancer pool health checks¶
Health checking support has been introduced for OVN load balancer backend pools.
Administrators can configure active health checks using the healthcheck settings on the pool, specifying interval, timeout, and consecutive success/failure thresholds.
The health state of backend instances can be inspected via the new load balancer pool state API.
Documentation: How to configure network load balancers
API extension: network_load_balancer_pool_health_checks
Pure Storage FlashArray Fibre Channel support¶
The Pure Storage FlashArray storage driver has expanded enterprise SAN connectivity options by adding Fibre Channel transport support.
Storage pools can now be configured using SCSI over Fibre Channel (pure.mode=scsi/fc) or NVMe over Fibre Channel (pure.mode=nvme/fc), complete with automatic initiator WWPN discovery and volume registration.
Documentation: Pure Storage - pure
API extensions: storage_driver_pure_scsifc and storage_driver_pure_nvmefc
Dell PowerStore NVMe support¶
The Dell PowerStore storage driver now supports NVMe over TCP (nvme/tcp) and NVMe over Fibre Channel (nvme/fc) transport modes.
NVMe/TCP is now configured as the default connectivity mode when creating new PowerStore storage pools without an explicit powerstore.mode setting.
Documentation: Dell PowerStore - powerstore
API extension: storage_driver_powerstore_nvme
Identity effective groups and state endpoint¶
A new identity state API endpoint and recursion=2 listing mode have been introduced to provide visibility into effective group memberships.
The endpoint computes and returns the effective_groups for an identity, reporting the union of direct authorization groups and mapped OIDC identity provider groups.
Documentation: Remote API authentication
API extension: access_management_identity_effective_groups
Credential expiry reporting¶
The Identity API struct now includes an expires_at field across all identity listing and inspection endpoints.
This exposes the expiration date of client TLS certificates and issued bearer tokens, enabling proactive rotation and monitoring of client credentials before expiry.
Documentation: Remote API authentication
API extension: access_management_expiry
Pending states for bearer identities¶
LXD introduces pending identity types (Client token bearer (pending), DevLXD token bearer (pending), and Initial UI token bearer (pending)).
Bearer identities are created in a pending state until a valid token is issued, and automatically revert to the pending type if their token is revoked, providing clear lifecycle tracking for bearer access.
Documentation: Remote API authentication
API extension: access_management_bearer_pending
Durable operations¶
A new durable operation class has been introduced for mission-critical daemon workflows.
Durable operations persist their state in the cluster database. If the cluster member executing the operation fails or goes offline, the operation is automatically resumed on the DQLite raft leader once heartbeat timeouts elapse.
Documentation: REST API
API extension: durable_operations
Dedicated server state endpoint¶
A dedicated GET /1.0/state endpoint has been added to retrieve server status.
This API endpoint is only available when LXD is in standalone mode.
When clustered, the GET /1.0/cluster/members/{name}/state endpoint should be called.
This allows clients and monitoring tools to quickly inspect system and storage pool state.
Documentation: REST API
API extension: server_state
CDI passthrough for NVIDIA MIG GPUs¶
GPU passthrough for gputype=mig devices has transitioned to the Container Device Interface (CDI) instead of legacy nvidia.runtime mechanisms.
Administrators can supply CDI identifiers directly in the device’s id property or continue specifying mig.uuid or mig.gi/mig.ci pairs, which LXD resolves automatically to CDI devices via NVML.
Documentation: Type: gpu
API extension: gpu_mig_cdi
Operation child count and child listing¶
The Operation struct now includes a child_count field, allowing callers to determine whether an operation has spawned child operations without issuing recursive queries.
In addition, the lxc operation command now includes a list-children subcommand.
Documentation: REST API
API extension: operation_child_count
Operation wait status code reporting¶
The operation wait endpoints now return the failed operation state and error status code upon failure.
This ensures callers and DevLXD clients receive immediate and accurate error diagnostics when long-running background tasks terminate with an error.
Documentation: REST API
API extension: operation_wait_status_code
VM volatile max vCPUs tracking¶
Virtual machines now track maximum configured vCPUs in volatile configuration keys.
This preserves CPU hotplug boundaries across instance life cycles and enables live migration of virtual machines between cluster members with differing CPU core counts.
Documentation: Instances
API extension: vm_volatile_maxcpus
Loki configuration readiness check¶
LXD now optionally skips Loki API endpoint readiness checks before attempting to transmit log streams.
This improves compatibility with OpenTelemetry (OTLP) and Canonical Observability Stack (COS) deployments.
Documentation: Provided metrics
API extension: loki_config_api_check_ready
Optional project replica mode¶
The replica_mode attribute is now omitted for projects that do not participate in disaster recovery replication topologies.
A new lxc project clear-replica command has also been added to clear replica state and promote/demote guard rails from projects.
Documentation: Projects
API extension: project_replica_mode_optional
Bug fixes¶
The following bug fixes are included in this release.
Fix physical network parent sharing across VLANs in clustered mode Fix failed file operation due to deleted forkfile as a result of race condition Acquire lock before reading read-only operation flag in lxd-agent Fix snapshot table layout in lxc info when no volume snapshots exist Fix SRIOV VF used count and total disk allocated in lxc info Detect download cancellation with errors.Is in simplestreams client Fetch network state when filtering instances by IP address in lxc list Include server operations when listing operations in default project Fix STARTTLS peek blocking the accept loop in endpoint listeners Fix LXCFS clean up logic and avoid generating new certificates on running instances Allow volume security.shifted and directory shift when raw.idmap is set on VM Preserve protected configuration keys during replicator refresh Restrict image reuse to cached images with identical image source Fix stacked tmpfs mounts for shared mounts and migrate legacy devlxd path Keep target volatile configuration keys on migration refresh Fix VM live migration between cluster members with different CPU counts Refuse to delete or rename a cluster link referenced by a project replica.cluster Distinguish unassigned LUN from LUN 0 in Pure Storage driver Prevent refused replicator refresh from leaving source configuration on target Associate advertised BGP prefixes with their owning peer session Make cluster member restore conflict with ongoing evacuations
Backwards-incompatible changes¶
These changes are not compatible with older versions of LXD or its clients.
NVIDIA legacy instance-level configuration removed¶
The legacy instance-level NVIDIA configuration options (nvidia.runtime, nvidia.driver.capabilities, nvidia.require.cuda, and nvidia.require.driver) have been removed.
In addition, the nvidia_runtime and nvidia_runtime_config API extensions have been removed.
Existing instances, instance snapshots, and profiles will have these legacy options cleaned up automatically on daemon upgrade.
NVIDIA GPU passthrough should now be configured using the Container Device Interface (CDI) passthrough.
Documentation: Type: gpu
Cluster healing functionality removed¶
The cluster healing feature and its server configuration setting cluster.healing_threshold have been removed.
In addition, the cluster_healing API extension has been removed.
Automatic evacuation and eviction of unresponsive cluster members has been discontinued to avoid accidental quorum loss during transient network partitions.
Known issues¶
This section covers known temporary limitations and integration regressions in this release.
CDI GPU passthrough failure on Ubuntu Core 26¶
Users attempting to pass through GPUs to containers on Ubuntu Core 26 environments using the gpu-2604 interface (provided by the mesa-2604 snap) will encounter a container startup failure:
Error: Failed starting device "gpu0": Failed generating CDI spec: Failed determining NVIDIA driver root path: Failed running: /snap/lxd/<revision>/gpu-2604/bin/gpu-2604-provider-wrapper printenv NVIDIA_DRIVER_ROOT: exit status 1
This is caused by an upstream architectural mismatch on the Core 26 track between the pc-kernel snap and the mesa-2604 graphics provider snap.
There is currently no native LXD configuration workaround. We are working with our partners to resolve the issue.
Ceph userspace tooling incompatibility¶
LXD bundles Ceph userspace tooling to manage ceph, cephfs, and cephobject storage pools, volumes, and buckets.
The version of this tooling is incompatible with the most recent Ceph OSD release.
New deployments should use a version of MicroCeph that packages a Ceph version before 20.2.4 (tentacle) or 19.2.6 (squid). Existing deployments that upgrade MicroCeph to a version that contains the newer Ceph must not rotate keys until the newer key type is compatible with the client shipped by LXD.
Updated minimum Go version¶
If you are building LXD from source instead of using a package manager, the minimum version of Go required to build LXD is now 1.27.1.
Snap packaging changes¶
Shipped
qemu-nbdandqemu-storage-daemonbinaries to support persistent changed block tracking.Shipped
virtiofsdon all architectures with virtual machine support (enabling non-amd64 architectures, except armhf).QEMU bumped to version 10.2.1+ds-1ubuntu3.2.
EDK2 firmware bumped to 2025.11-3ubuntu7.2, shipping both Secure Boot and non-Secure Boot firmware variants.
Reintroduced the KVM vAPIC option ROM for 32-bit BIOS guests in QEMU.
Bumped ZFS to versions 2.2.11, 2.3.9, and 2.4.4 across respective branches.
Bumped NVIDIA container toolkit and libnvidia-container to v1.20.1.
Bumped LXC and LXCFS to v7.0.0 LTS.
Enabled building LXD UI and documentation on riscv64.
Change log¶
Downloads¶
The source tarballs and binary clients can be found on our download page.
Binary packages are also available for:
Linux:
snap install lxd --channel=6/stablemacOS client:
brew install lxcWindows client:
choco install lxc