From 3ac73c7727106f393b7db1a914a50ec0bcd20013 Mon Sep 17 00:00:00 2001 From: KATOH Yasufumi Date: Mon, 28 Sep 2026 22:37:33 +0900 Subject: [PATCH] Add Japanese release announcement of Incus 7.5 Reviewed-by: Hiroaki Nakamura Signed-off-by: KATOH Yasufumi --- .../news.ja/incus-7-5-has-been-released.yaml | 715 ++++++++++++++++++ 1 file changed, 715 insertions(+) create mode 100644 content/incus/news.ja/incus-7-5-has-been-released.yaml diff --git a/content/incus/news.ja/incus-7-5-has-been-released.yaml b/content/incus/news.ja/incus-7-5-has-been-released.yaml new file mode 100644 index 00000000..438589f2 --- /dev/null +++ b/content/incus/news.ja/incus-7-5-has-been-released.yaml @@ -0,0 +1,715 @@ +title: Incus 7.5 リリースのお知らせ +date: 2026/09/25 15:30 +origin: https://discuss.linuxcontainers.org/t/incus-7-5-has-been-released/27273 +content: |- + + Incus チームは、Incus 7.5 のリリースのアナウンスができてうれしいです! + + + 今回のリリースでは、ストレージ、ネットワーク、クラスタリング、アクセスコントロール、OCI コンテナ、エージェントサポートの改良など、あらゆるユーザーにとって役に立つ新機能を多数導入しました。また、大規模環境におけるパフォーマンスが大幅に向上し、様々なバグやセキュリティの問題も修正しました。 + + [![image|690x322](https://discuss.linuxcontainers.org/uploads/default/original/2X/6/6b40d2360eb7b12e42df590b41fdcab65667a602.png)](https://linuxcontainers.org/incus/try-it/) + + + いつものように、オンラインでご自身で試せます: [Linux Containers - Incus - オンラインでの試用](https://linuxcontainers.org/ja/incus/try-it/) + + + 注意: 実際にダウンロードするリリースバージョンは 7.5.1 になります。7.5.0 はリリースに必要な成果物の一部が生成されず、再リリースが必要になりました。 + + # セキュリティ修正 + + + このリリースでは、11 の脆弱性を修正しました: + + - [CVE-2026-85185](https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p) (critical) - 最適化されたバックアップとマイグレーションにおける btrfs サブボリュームのパストラバーサルを介したホスト上での任意のファイル削除とディレクトリー配置 + - [CVE-2026-85526](https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv) (critical) - 最適化されたバックアップにおける btrfs サブボリュームのパストラバーサルを介したホスト上のファイル削除とディレクトリー配置 + - [GHSA-443p-7392-h4v2](https://github.com/lxc/incus/security/advisories/GHSA-443p-7392-h4v2) (medium) - 制限付きプロジェクトが、クラスターリフレッシュを通して pull モードを使える + - [GHSA-4cph-ccqv-hm3c](https://github.com/lxc/incus/security/advisories/GHSA-4cph-ccqv-hm3c) (critical) - ボリューム更新、コピー、移動を介した `block.create_options` に対するプロジェクト制限の回避 + - [GHSA-579w-c4rw-c8q3](https://github.com/lxc/incus/security/advisories/GHSA-579w-c4rw-c8q3) (critical) - マイグレーションストリーム内のシンボリックリンクを介したホスト上の任意のファイルへの書き込み + - [GHSA-hpjh-q53p-f27r](https://github.com/lxc/incus/security/advisories/GHSA-hpjh-q53p-f27r) (critical) - インスタンスバックアップ依存ボリューム内のパストラバーサルを介したホスト上の任意のファイルへの書き込み + - [GHSA-jh4v-j34r-2mgh](https://github.com/lxc/incus/security/advisories/GHSA-jh4v-j34r-2mgh) (high) - ソースタイプを省略したカスタムボリュームコピーのプロジェクト制限の回避 + - [GHSA-mfwv-x733-9446](https://github.com/lxc/incus/security/advisories/GHSA-mfwv-x733-9446) (medium) - 認証バイパスにより、制限つきクライアントが他のプロジェクトのあらゆる操作を読み取れる + - [GHSA-mmj7-8rgf-mx2h](https://github.com/lxc/incus/security/advisories/GHSA-mmj7-8rgf-mx2h) (high) - 事前署名されたS3アップロードURL上の署名なしヘッダーを介した他のバケットオブジェクトの読み取り + - [GHSA-wfvq-qh87-gm4j](https://github.com/lxc/incus/security/advisories/GHSA-wfvq-qh87-gm4j) (medium) - Incus CLI による再帰的なファイルのプル中の悪意のある `incus-agent` を介した任意のファイルへの書き込み + - [GHSA-x8gj-2q73-qr6j](https://github.com/lxc/incus/security/advisories/GHSA-x8gj-2q73-qr6j) (high) - 制限付きクライアントがデフォルトプロジェクトのストレージバケットキーを読み取ることができる + + # 新機能 + ## OVN 子ネットワーク + + OVN ネットワークは、同じプロジェクト内の別のネットワークを指す `parent` を指定して作成できるようになりました。 + + + 子ネットワークは、独自の論理ルーターを持つのではなく、その論理スイッチとサブネットを親ネットワークの論理ルーターに接続します。これにより、複数の内部サブネットを単一の論理ルーターでルーティングし、アップリンク、外部アドレス、ピアリングを共有できるようになります。 + + stgraber@vorash:~$ incus network create net1 --type=ovn network=UPLINK ipv4.address=192.0.2.1/24 + stgraber@vorash:~$ incus network create net2 --type=ovn parent=net1 ipv4.address=198.51.100.1/24 + stgraber@vorash:~$ incus launch images:debian/13 c1 --network net2 + + + 子ネットワークは独自のサブネット、DHCP、DNS レコード、ACL、インスタンスポートを保持します。親ネットワークとは独立して NAT を有効化でき、`ipv4.nat.address` や`ipv6.nat.address` を使用して独自のアドレスへ転送できます。これにより、あるサブネットを NAT 変換する一方で、別のサブネットは同じルーター上でネイティブにルーティングすると言った構成が取れるようになります。 + + + ピアリングは親ネットワークによって処理され、その子ネットワークのすべてのサブネットをカバーします。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/reference/network_ovn/#child-networks + + ## プロジェクトのクラスター内のライブによる移動 + + `--target-project` と `--target` を組み合わせることで、実行中のインスタンスを、別のクラスターメンバーへのライブマイグレーションの一環として、異なるプロジェクトに移動できるようになりました。 + + stgraber@vorash:~$ incus move v1 --target incus02 --target-project prod + + + ターゲットプロジェクトでも、インスタンスのデバイス構成が同一である必要があります。 + `dependent` としてマークされたカスタムボリュームは、インスタンスとともに移動します。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/howto/move_instances/ + + ## カスタムボリュームディスクの初期コピー + + カスタムストレージボリュームをバックエンドにし、コンテナにアタッチされる `disk` デバイスに、`initial.copy` プロパティーが追加されました。 + + + これを `true` に設定すると、ボリュームが空の状態で初めて使用される時に、コンテナ内のデバイスの `path` に存在するコンテンツがボリュームにコピーされます。これは、アプリケーションコンテナが期待する、あとでボリュームがマウントされるディレクトリー内にデータを格納する際の動作と整合性が取れています。 + + stgraber@vorash:~$ incus storage volume create default mysql-data + stgraber@vorash:~$ incus config device add mysql data disk pool=default source=mysql-data path=/var/lib/mysql initial.copy=true + + + コピーはボリュームごとに一度だけ実行され、そのことはボリュームの `volatile.initial.copied` キーに記録されます。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/reference/devices_disk/#initial-copy + + ## インスタンスセキュリティータグ + + カンマ区切りのタグのリストを設定する `security.tags` インスタンス設定キーが新たに追加されました。 + + + Incus 自身は、このタグを認証の判断には使用せず、認証バックエンドに対して公開します。OpenFGA の場合、それぞれのタグが `security_tag` オブジェクトとなり、保持する `tag` リレーションを通して、そのタグを持つすべてのインスタンスと関連付けられます。 + + stgraber@vorash:~$ incus config set c1 security.tags=pci,production + + ドキュメント : https://linuxcontainers.org/incus/docs/main/authorization/#security-tags + + ## 認証スクリプトレット内の OIDC クレーム + + 認証スクリプトレットに渡される `details` 引数に、クライアントが認証済み OIDC クレームを持つ `Claims` フィールドが追加されました。 + + + これにより、スクリプトレット内で別途マッピングを持つことなく、`groups` や `email` のような ID プロバイダーから提供される任意のクレームに基づくルールを書くことができます。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/authorization/#scriptlet + + ## クラスターメンバーメトリクス + + `/1.0/metrics` エンドポイントが、クラスターメンバーの情報を報告するようになりました: + + - `incus_cluster_member` メンバーのアーキテクチャーと障害ドメイン + - `incus_cluster_member_status` 可能性のあるステータスごとに 1 つのサンプル + - `incus_cluster_member_role` ロールごとに 1 つのサンプルを保持 + - `incus_cluster_member_group` メンバーが属するグループごとに 1 つのサンプル + + + これにより、簡単に Prometheus から直接、オフラインもしくは退避したメンバーに関するアラートを発信できます。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/reference/provided_metrics/ + + ## 仮想マシン向け NVIDIA GPUDirect P2P + + 仮想マシンにパススルーされる物理的な `gpu` デバイスに、`nvidia.clique` 設定キーを追加されました。 + + + 同じ仮想マシンに割り当てられた複数の GPU に対して同じ clique ID(0〜15)を設定すると、それらはゲストドライバーに対して GPUDirect P2P clique として認識され、GPU 間で直接的な DMA が可能になります。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/reference/devices_gpu/ + + ## Windows エージェントの改良 + + Windows エージェントで対話型 `incus exec` セッションが可能になり、シグナル転送処理も改良されました。 + + ## NetBSD 仮想マシン + + Incus エージェントは、既存の Linux、FreeBSD、macOS、Windows サポートに加えて、NetBSD ゲストが利用可能になりました。 + + + 他の BSD 系と同様に、`image.os` に `NetBSD` で始まる値を設定すると、仮想マシンに対して必要なチューニングが自動的に適用されます。 + + ## FreeBSD クライアントパッケージ + + Incus クライアントは FreeBSD Ports にパッケージ化されており、`pkg install incus-client` コマンドでインストールできます。各リリースにはあらかじめビルドされたクライアントバイナリーも含まれています。 + + ## ファイル転送のアーカイブモード + + `incus file push` と `incus file pull` に `--archive`(`-a`)フラグが追加されました。`cp -a` のように動きます。 + + + 所有権、モード、タイムスタンプは `--archive`(`--recursive` も含む)を使用したときだけ保持されるようになりました。通常の転送は、単純な `cp` コマンドと同様に動作します。 + + stgraber@vorash:~$ incus file pull --archive c1/etc/ ./etc-backup/ + + ## OCI イメージラベルと環境 + + OCI レジストリーからインポートされたイメージは、`oci.*` イメージプロパティーとして、標準ラベル(`org.opencontainers.image.*`)を公開するようになりました。これにより、イメージタイトル、バージョン、ソース、説明などが `incus image info` で確認できるようになり、新しいイメージプロパティー列で利用できるようになります。 + + + イメージ環境は、インスタンス作成時にインスタンス構成にコピーされなくなりました。代わりに、`incus exec` のデフォルト環境として使われます。インスタンスの設定をクリーンに保ちつつ、イメージの更新を通して環境の変更を反映できるようになります。 + + ## ブリッジ DNS ホストレコード + + `bridge` ネットワークに `dns.include_hosts` 設定キーが追加されました。これにより、ネットワークの `dnsmasq` がホストの `/etc/hosts` ファイルからレコードを提供するかどうかを制御できるようになります。 + + + これを `false` に設定すると、AppArmor による制限を保ちつつ、ホスト専用のエントリーがインスタンスに公開されるのを防ぐことができます。 + + ドキュメント : https://linuxcontainers.org/incus/docs/main/reference/network_bridge/ + + ## API を通したプロファイリング + + `incusd` の Go `pprof` プロファイルが、各リスナーの `/internal/debug/pprof/` 以下で利用できるようになりました。ただし、アクセスはサーバーの管理権限を持つクライアントに制限されています。 + + + `core.debug_address` と異なり、これは、HTTPS 経由で、サーバー設定の変更なしに動作します。 + + stgraber@vorash:~$ incus query --raw my-remote:/internal/debug/pprof/heap > heap.pprof + stgraber@vorash:~$ go tool pprof heap.pprof + + ドキュメント : https://linuxcontainers.org/incus/docs/main/debugging/#profiling-incusd + + # すべての変更点 + + + このリリースのすべての変更のリストは次のとおりです(翻訳なし): + + [details="すべてのChangeLogを見る"] + - incus-agent: Abstract exec process handling + - incus-agent: Report exit status of Windows exec sessions + - incus-agent: Fix PATHEXT for Windows exec sessions + - incus-agent: Forward exec signals on Windows + - incus-agent: Support interactive exec sessions on Windows + - incusd/instance/edk2: Add FirmwarePair.HasNVRAM + - incusd/scriptlet/qemu: Handle firmwares without NVRAM + - incusd/instance/qemu: Skip NVRAM handling with SeaBIOS firmware + - doc: Note NVRAM scriptlet functions need EDK2 firmware + - incusd: Validate OCI config.json before use + - incusd: Consistently say 'an NVRAM' + - incusd/instance/qemu: Close NVRAM file after writing + - incusd/instance/qemu: Never drop runtime state while QEMU is alive + - incusd/instance/qemu/qmp: Raise default command timeout to 2s + - client/oidc: Route provider requests through a dedicated transport + - client/oidc: Drop empty form parameters sent to the provider + - incusd/device: Allow importing dependent volumes with snapshots + - tests: Check dependent volume snapshots survive export/import + - incusd/storage/drivers: Add cluster size to qcow2 ImageInfo + - incusd/instance/qemu: Advertise qcow2 cluster size as discard granularity + - internal/io: Add GetUmask and Lchtimes helpers + - incus/file: Add --archive to file push/pull + - tests: Add --archive file transfer coverage + - i18n: Update translation templates + - incus/cluster: Don't use unix socket URL as the join address + - incus-agent: Externalize PTY logic + - incus-agent: Basic signal handling on Windows + - incus-agent: Add NetBSD agent + - incusd/instance/agent-loader: Add NetBSD files + - incusd/instance/agent-loader: Rename FreeBSD rc.d directory + - shared/osinfo: Add NetBSD + - incusd/instance/qemu: Add NetBSD support + - goreleaser: Add NetBSD + - doc/instance/create: Add NetBSD and update other agents + - github: Tune shellcheck exclusions + - doc/wordlist: Update wordlist + - Translated using Weblate (German) + - Translated using Weblate (German) + - Translated using Weblate (German) + - Translated using Weblate (German) + - Translated using Weblate (German) + - Translated using Weblate (Spanish) + - Translated using Weblate (Spanish) + - Translated using Weblate (Spanish) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (French) + - Translated using Weblate (Italian) + - Translated using Weblate (Italian) + - Translated using Weblate (Japanese) + - Translated using Weblate (Japanese) + - Translated using Weblate (Japanese) + - Translated using Weblate (Japanese) + - Translated using Weblate (Dutch) + - Translated using Weblate (Dutch) + - Translated using Weblate (Portuguese (Brazil)) + - Translated using Weblate (Portuguese (Brazil)) + - Translated using Weblate (Portuguese (Brazil)) + - Translated using Weblate (Russian) + - Translated using Weblate (Russian) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Chinese (Simplified Han script)) + - Translated using Weblate (Portuguese) + - Translated using Weblate (Portuguese) + - Translated using Weblate (Portuguese) + - Translated using Weblate (Norwegian Bokmål) + - Translated using Weblate (Norwegian Bokmål) + - Translated using Weblate (Indonesian) + - Translated using Weblate (Indonesian) + - Translated using Weblate (Indonesian) + - Translated using Weblate (Chinese (Traditional Han script)) + - Translated using Weblate (Chinese (Traditional Han script)) + - Translated using Weblate (Tamil) + - Translated using Weblate (Swedish) + - Translated using Weblate (Swedish) + - Translated using Weblate (Swedish) + - Translated using Weblate (Greek) + - Translated using Weblate (Georgian) + - Translated using Weblate (Georgian) + - Translated using Weblate (Portuguese) + - incusd/instance: Mention images available for other instance types + - incusd/images: Check source instance access on publish + - incusd/cluster: Wait for all blocking instance operations before evacuating + - incusd/instance: Apply evacuation guard to forwarded state changes + - incusd/instance/lxc: Check liblxc state when tolerating stop failures + - incusd/instance: Balance NUMA nodes on committed memory + - incusd/cluster: Stop Ready and Frozen instances before a restore migration + - incusd/instance: Reject stateless cluster moves of running instances + - incusd/device/tpm: Mount the instance volume when removing state + - incusd/instances: Prefer images.default_architecture for multi-arch sources + - incusd/instance/qmp: Split query and operational command timeouts + - incusd/instance/qmp: Tolerate monitor timeouts in blockJobWait + - incusd/instance/qemu: Report busy monitor as running + - incusd/instance/qemu: Log failure to resume after failed migration + - incusd/instance/qemu: Wait for the NBD server before blockdev-add + - incusd/instance/qemu: Accept qemu-kvm binary name in PID validation + - incus/image: Don't warn on already closed files during import + - Set PKCE challenge and verifier values + - cmd/generate-database/db: Add nullable field support + - incusd/network/bridge: Clean up tunnel interfaces on failed start + - incusd/network/physical: Restore the original MTU on stop + - incusd/instance: Treat pool and project changes as migrations + - api: network_bridge_dns_include_hosts + - incusd/network/bridge: Add dns.include_hosts + - doc: Update configs + - tests: Add dns.include_hosts test + - incusd/db/query: Fix giving-up warning in Retry + - incusd/cluster: Fix IsCowsqlNode return value + - incusd/cluster: Fix lock leak in heartbeat Send + - incusd/cluster: Fix typos + - doc: Mention FreeBSD client + - incusd: Restore in-memory config when update triggers fail + - incusd/config: Distinguish unset keys from explicit defaults + - tests: Add server config default value test + - incusd: Allow unsetting OVN connection when no OVN network exists + - tests: Add OVN server config test + - incusd/network/ovn: Inherit uplink bridge MTU when none is configured + - tests: Check OVN uplink veth MTU + - incusd: Don't close a nil pipe reader on backup failure + - incusd/storage/ceph: Fix qemu-nbd image spec + - tests: Add ceph librbd test + - github: Install qemu with librbd support for ceph tests + - cmd/incus: Remove url escape for spice socket path. + - incusd/storage/drivers: Add ReconnectQemuNbd and DisconnectQemuNbdWait + - incusd/storage/ceph: Reconnect NBD devices in place after resize + - tests: Add ceph-librbd driver to VM storage suites + - github: Run VM storage tests on ceph-librbd + - incus-agent: Fix paths on BSDs + - incus-agent: Factor code for UNIXes + - incus-agent: Please gofumpt + - incusd/instance/qemu/qmp: Be lenient about events with trailing \r + - incusd/instance/qemu: Disable multiport serial on NetBSD + - incusd/instance/drivers: Update serial tests + - doc/instance/create: Document new NetBSD tuning + - incusd/instance/config: Add volatile.last_state.agent.once + - incusd/instance/qemu: Make template application more robust + - doc: Update config + - incusd/instance/qemu: Remove unused argument + - incusd: Fix typo + - incusd/instance/agent-loader: Log agent output + - doc: Add multiport to wordlist + - incusd/rsync: Only transfer xattrs settable without CAP_SYS_ADMIN + - incusd/storage/zfs: Delete target volume before full transfer on refresh + - internal/linux: Add SparseFileWrapper + - incusd/storage: Use linux.SparseFileWrapper + - incusd/cluster/evacuation: Stop in place when scriptlet has no candidates + - incusd/mirror: Add file mirroring package + - internal/linux: Add SetMountReadOnly + - incusd/device/tpm: Run swtpm on a local mirrored copy of its state + - incusd/instance/qemu: Run QEMU on a local mirrored copy of the UEFI variables + - incusd/instance/qemu: Make the config volume read-only during live migration on shared storage + - incusd/storage: Flush local instance state before snapshots, copies and backups + - incusd/storage/drivers: Repair VM config volumes with recorded errors before mounting + - incusd/scriptlet: Track pending instance placements + - incusd/cluster/evacuation: Serialize target selection and record pending placements + - incusd/instance: Reserve NUMA nodes for starting and incoming instances + - incusd/apparmor/rsync: Allow reading destination ancestors + - incusd/api: Exclude node-local config from untargeted cluster ETag + - incusd/cluster: Reject internal rebalance/handover requests during startup + - incus/device: Set NVIDIA device UUIDs for physical GPUs + - incusd/storage/drivers: Add generic property cache + - incusd/storage/zfs: Use generic property cache + - incusd/storage/truenas: Use generic property cache + - incusd/storage/linstor: Add getVolumeIndex + - incusd/storage/linstor: Use filesystem stats for mounted volumes + - incusd/storage/linstor: Cache volume usage lookups + - incusd/storage/lvm: Cache thin volume usage lookups + - incusd/ovn: gofumpt + - incusd/instance/qmp: Handle ringbuf-read racing a chardev swap + - incusd/instance/qemu: Make ConsoleLog tolerant of concurrent console attach + - incusd/instance/lxc: Record migration transfer errors before signaling completion + - incusd/instance/qemu: Record migration transfer error before signaling completion + - incusd/project: Delete network peers on forced project deletion + - tests: Check forced project deletion with OVN peers + - incusd/images: Return error on invalid export request + - incusd/images: Preserve image type on push mode copy + - Translated using Weblate (Georgian) + - incusd/network/ovn: Limit initial connection setup + - incusd/network/ovn: Fail fast and name the database when unavailable + - incusd/network/acl: Resolve profile projects in a single transaction + - incusd/network/address-set: Resolve profile projects in a single transaction + - incusd/network/ovn: Scope mutual peer lookups to the target network + - incusd/instance/qemu: Don't pass nil exec streams to the agent client + - internal/server/storage/drivers: Handle dotted Ceph client IDs + - internal/server/util: Recognize named unconfined AppArmor profiles + - internal/server/instance/drivers: Unmount residual Unix devices during cleanup + - incusd/project: Fix unrestricted project check on volatile keys + - incusd/project: Allow snapshot restore with changed volatile keys + - tests: Add restricted project snapshot restore test + - tests: Cover OVN peering with several peers on one network + - incusd/instance/qmp: Make clearing the event handler sticky + - incusd/instance/qemu: Ignore duplicate stop hooks + - incusd/instance/lxc: Reuse exact-sized ID map gaps + - tests: Check exact-sized isolated ID map reuse + - api: gpu_physical_clique + - incusd/device/gpu: Add clique option to physical GPUs in VMs + - incusd/instance/qemu: Set x-nv-gpudirect-clique on passed-through GPUs + - doc: Document GPU clique option + - doc: Add DMA and GPUDirect to wordlist + - doc: Update configs + - incusd/instance: Fix project change dropped on cross-member moves + - tests: Add cross-project cluster move tests + - client: Don't attempt reconnection on websocket operations + - incusd/storage/zfs: Clean up parent dataset on failed migration + - shared/scriptlet: Flatten embedded pointer structs when marshalling + - api: authorization_scriptlet_claims + - incusd/request: Add OIDC claims context keys and forwarding header + - incusd/auth/oidc: Return validated claims from Auth + - incusd: Store validated OIDC claims in the request context + - incusd/cluster: Forward OIDC claims to other members + - incusd/auth: Expose OIDC claims to the authorization scriptlet + - doc: Document the Claims field of the authorization scriptlet + - incusd/mirror: Don't prune persistent files on start + - incusd/instance/qemu: Regenerate NVRAM when the symlink is dangling + - incus/server/network/driver/common: Remove loadbalancer bgp prefix on network delete + - incusd/instances: Log instance rendering failures + - incusd/backup: Fall back to the index config when backup.yaml is missing + - tests: Import a backup without backup.yaml + - incusd/firewall/nftables: Replace bridge filter chains atomically + - incusd/device/nic/bridged: Keep existing filters when an update fails + - incusd/network/acl: Reject rules the host firewall can't apply + - incusd/network/bridge: Validate ACL actions against the host firewall + - incusd/device/nic/bridged: Validate ACL actions against the host firewall + - doc: Note that allow-stateless is OVN only + - client: Fail clearly when OIDC provider has no device authorization endpoint + - incusd/instance/lxc: Hold the ID map lock until the allocation is persisted + - tests: Check concurrent isolated ID map allocation + - incusd/network/ovn: Match IPv6 load balancer health monitors + - incusd/instance: Add OCI config helpers + - incusd/instance/lxc: Export the OCI image environment as defaults + - incusd: Use the OCI image environment as exec defaults + - incusd: Stop copying the OCI environment into the instance config + - tests: Check OCI environment overrides and rebuild + - api: instance_project_move_live + - incusd/instance: Reject project moves when an attached volume can't follow + - incusd/instance: Reject project moves of instances with backups + - incusd/instance: Allow live project moves within a cluster + - incusd/instance: Resolve the volume project when removing dependent volumes + - incusd/storage: Fix migration type negotiation for dependent volumes + - incusd/instance: Pass the cluster move flag when negotiating dependent volume types + - incusd/instance: Let dependent volumes follow an instance across projects + - doc: Document live project moves + - tests: Add cross-project move tests + - incusd/instance/qemu: Reject live migration of filesystem dependent volumes + - incusd/storage: Resolve the volume project for dependent volumes + - incusd/instance: Resolve the volume project when deleting dependent volumes + - incusd/instance: Resolve the volume project for near-live dependent volume transfers + - incusd/instance: Let dependent volumes on local pools follow a project move to another member + - doc: Document dependent volumes in project moves with shared storage volumes + - tests: Add tests for dependent volumes in projects sharing storage volumes + - incusd: Keep the OS API reachable during shutdown + - incusd: Bound instance stops during shutdown + - incusd: Let a forced shutdown override one in progress + - incusd/storage/lvm: Use shared activation for ISO volumes on clustered pools + - incusd/storage/lvm: Rename both volumes of VM snapshots + - incusd/storage/lvm: Keep the original volumes until a restore fully succeeds + - tests: Rename VM snapshots before restoring them + - incusd/device: Reject unknown GPU types instead of passing through + - incusd/apparmor: Allow reading the local QEMU data directory + - tests: Check unknown GPU types are refused + - incusd/storage/zfs: Only reset datasets overriding the systemd ignore flag + - tests: Check delegated child datasets are reset + - incusd/firewall/nftables: Don't widen ACL rules for the other IP family + - tests: Check mixed-family ACL rule rendering + - incusd/firewall/nftables: Match ICMP on l4proto in ACL rules + - incusd/device/nic/bridged: Don't require br_netfilter for IPv6 filtering + - incusd/firewall/nftables: Allow DHCPv4 discovery through the forward chain + - tests: Check DHCPv4 exception and ICMPv6 ACL rendering + - incusd/firewall/nftables: Replace address set members in one transaction + - incusd/network/address-set: Reject overlapping addresses + - tests: Check a rejected address set edit keeps the applied set + - tests: Check bridged NIC ACL failures keep the filters + - incusd/instance: Don't shadow the project package name + - incusd/project: Re-check limits when recording instances and volumes + - incusd/storage: Check project limits when moving custom volumes + - incusd/cluster: Don't run update trigger under the gateway lock + - incusd/network/zone: Refresh TSIG cluster-wide and notify peers on creation + - incusd/network/bridge: Notify DNS peers on network update + - incus/remote: Make remote name checks stricter + - shared/cliconfig: Include diagnosis data in error path + - incus/usage: Defer remote error handling and clarify messages + - incus/list: Clarify --all-remotes usage + - incus: Hint missing space after remote on empty match list + - i18n: Update translation templates + - api: metrics_cluster_members + - incusd/metrics: Add cluster member metric types + - incusd/metrics: Add cluster member info, status and role metrics + - tests: Check cluster member metrics + - doc: Document cluster member metrics + - Added incant to the list of third party software + - Translated using Weblate (Portuguese) + - incusd/cluster: Include member lookups in heartbeat round duration + - incusd/cluster: Stamp member heartbeats at write time + - incusd/db: Add GetNICConflictCandidateIDs + - incusd/device/nic_bridged: Only load instances that may conflict + - incusd: Only query local instances for forwarded instance listings + - incusd/instances: Load local instances in one query when listing all projects + - incusd/storage: Fix custom volume usage always reporting zero total size + - api: instance_security_tags + - incusd/auth: Add security tag object type + - incusd/auth: Add instance security tags to the authorizer interface + - incusd/auth: Add security tags to the OpenFGA model + - incusd/auth: Add security tag support to OpenFGA + - incusd/auth: Update generated OpenFGA model + - shared/validate: Add IsSecurityTagList + - incusd/instance: Add security.tags + - incusd/instance: Sync security tags with the authorizer + - incusd: Include security tags in OpenFGA resource sync + - incusd/patches: Add auth_openfga_security_tags + - doc: Update configs + - tests: Add OpenFGA security tags test + - doc: Document security tags + - internal/filter: Add RegexpToLike + - incusd/instances: Push simple name filters down to the database + - incusd/instances: Forward filters to other cluster members + - incusd/instance/qemu: Abort snapshot transfer on failed live migration + - incusd/instance: Reject security.idmap.base on isolated containers + - incusd/instance/lxc: Use fixed ID map bases on non-isolated containers + - incusd/patches: Disable isolation on containers with a fixed ID map base + - incusd/instance: Update security.idmap.base description + - doc: Update configs + - doc: Describe fixed ID map ranges + - tests: Cover fixed ID map ranges + - incusd/db: Turn nodeSpecificNetworkConfig into network type aware function + - incusd: Switch usages to network type aware IsNodeSpecificNetworkConfig + - incusd/network/ovn: Add DeleteLogicalRouterNATByLogicalIP + - incusd/network/ovn: Resolve the network owning the logical router + - incusd/network/ovn: Support networks sharing a logical router + - incusd/network/ovn: Add support for child networks + - incusd/network: Put OVN networks with a parent in the logical dependency group + - incusd/network/ovn: Handle child networks in router wide features + - api: network_ovn_parent + - doc: Document OVN child networks + - doc: Update configs + - tests: Add OVN child network tests + - incusd/seccomp: Retry pidfd_open with PIDFD_THREAD on ENOENT + - incusd/network/ovn: Don't load a self-referencing parent + - incus/server/storage/driver/ceph: Flatten image in background during instance creation + - incusd/storage/ceph: Only flatten clones and wait for it before deleting + - incusd/storage/ceph: Release the source snapshot after flattening + - incusd/storage/ceph: Describe background flattening for ceph.rbd.clone_copy + - doc: Update configs + - tests: Cover ceph.rbd.clone_copy=false copies + - api: Add disk_initial_copy extension + - incusd/storage: Add volatile.initial.copied volume key + - incusd/device/disk: Add initial.copy for custom volumes + - incusd/instance/lxc: Allow adding initial.copy disks to existing instances + - tests: Add initial.copy disk test + - doc: Document initial.copy + - doc: Update configs + - client/oci: Expose OCI image labels as oci.* image properties + - tests: Cover OCI image labels + - incusd/profiles: Check project restrictions on profile creation + - incusd/network/ovn: Route child networks through the parent's peerings + - incusd/network/acl: Match the child networks of a peer + - incusd/network/ovn: Allow NAT addresses on child networks + - tests: Cover peering and NAT addresses with OVN child networks + - doc: Document peering and NAT addresses on OVN child networks + - api: Add internal_debug_pprof extension + - incusd: Add /internal/debug/pprof + - tests: Cover /internal/debug/pprof over HTTPS + - doc: Document profiling through the API + - incusd/cluster: Disconnect source client after restore + - incusd/instance/qemu: Only watch console disconnection for text console + - incusd/console: Time out waiting for websockets to connect + - incusd/logging: Don't block event delivery when Loki can't keep up + - incusd/instance: Cache boot time when computing process start time + - shared/resources: Read interface counters from sysfs + - incusd/instance/qemu: Read NIC counters directly for metrics + - incusd/metrics: Reduce allocations when rendering metrics + - shared/resources: Parse the PCI ID database only once + - shared/resources: Avoid over-allocating when reading sysfs files + - shared/resources: Resolve udev links once and count processes cheaply + - Update gomod + - doc/rest-api: Refresh swagger YAML + - incus/file: Contain recursive pull symlinks + - incusd: Don't follow symlinks when receiving migration data + - incusd/storage: Treat volume creation with a source as a copy + - incusd/storage/drivers: Confine btrfs subvolume paths + - incusd/storage: Validate dependent volume names on backup import + - incusd/storage: Ignore backup project for dependent volumes + - incusd/storage/s3: Require x-amz-* headers to be signed + - incusd/operations: Check project access on operation get and wait + - incusd/operations: Hide access token operations from non-admins + - incusd/storage/buckets: Require can_edit to read bucket keys + - incusd/project: Restrict volume options on update and copy + - incusd/instances: Check project restrictions on clustered refresh + - Release Incus 7.5 + [/details] + + # ドキュメント + + Incus のドキュメントはこちらです: + + https://incus-ja.readthedocs.io/ja/latest/ (日本語訳) + https://linuxcontainers.org/incus/docs/main/ (原文) + + # パッケージ + + Incus の開発元は、通常リリースの tarball のみをリリースするため、公式の Incus パッケージはありません。Incus を実行するために使えるオプションを以下にいくつか示します。 + + ## Linux 上に Incus サーバーをインストールする + + Incus はほとんどの一般的な Linux ディストリビューションで利用できます。インストール手順の詳細は、Incus のドキュメントを参照してください。 + + https://incus-ja.readthedocs.io/ja/latest/installing/ (日本語訳) + https://linuxcontainers.org/incus/docs/main/installing/ (原文) + + ## Incus クライアントの Homebrew パッケージ + + Homebrew 経由で、Linux と macOS 向けにクライアントツールが利用できます。 + + https://formulae.brew.sh/formula/incus + + ## Incus クライアントの Chocolatey パッケージ + + Chocolatey 経由で、Windows ユーザー向けにクライアントツールが利用できます。 + + https://community.chocolatey.org/packages/incus/7.5.1 + + ## Incus クライアントの Winget パッケージ + + Winget 経由で、Windows ユーザー向けにクライアントツールが利用できます。 + + https://winstall.app/apps/LinuxContainers.Incus + + # サポート + + 月次のフィーチャーリリースは、次のリリースがリリースされるまでのみサポートされます。より長いサポート期間と少ない変更頻度が必要な場合、代わりに Incus 7.0 LTS の使用を検討すべきです。 + + コミュニティサポートはこちらから : https://discuss.linuxcontainers.org + 商用サポートはこちらから : https://zabbly.com/incus + バグはこちらから報告できます : https://github.com/lxc/incus/vissues