> For the complete documentation index, see [llms.txt](https://docs.platform9.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.platform9.com/release-notes/august-2026-release.md).

# August 2026 Release

This release of <code class="expression">space.vars.PRODUCT\_NAME</code> introduces new features, enhancements, and bug fixes. Highlights include a granular role-based access control model with dedicated administrative roles, VM-to-host affinity rules for stretched clusters spanning multiple failure domains, and continued maturity for vGPU and Platform9 OS (Rocky Linux) host support. Simple (Layer 2) networking also reaches general availability, alongside a broad set of storage, networking, and self-hosted deployment reliability fixes.

### Features and Enhancements

#### Compute

* **Platform9 OS (Rocky Linux by CIQ 10.2) GA:** unified host installer experience powered by [Platform9 OS](https://docs.platform9.com/private-cloud-director/2026.8/getting-started/getting-started#id-4.-platform9-os) is now Generally Available. Includes a new Host Management Console for easier host configuration.
* **Delete Associated Volumes and Ports With a VM:** when deleting a VM, you can now optionally select its attached volumes and network ports to delete at the same time.
* **Cross-Cluster Cold Migration:** VMs can now be cold-migrated between clusters.
* **Add a Host to a Cluster from the Clusters Grid:** you can now add an eligible, already-onboarded host to a cluster directly from the Clusters grid, without going through Edit Roles.
* **Change VM Tenant Ownership from the UI:** administrators can now change the tenant that owns a VM, including in bulk for multiple VMs, directly from the UI.
* **Cluster-Level CPU and Memory Allocation Ratios:** administrators can configure CPU and memory allocation ratios at the cluster level, with automatic propagation to every host in the cluster.
* **Safer VM Delete Controls:** VM deletion is now disabled while a VM is active, paused, or suspended, reducing accidental deletions from the UI.
* **NUMA Memory Policy Update**: The `hw:numa_mempolicy` flavor setting of 'preferred' is now honored, allowing VMs to spill over to another NUMA node under memory pressure instead of being OOM killed.
* **Multi-GPU Model Passthrough Per Host:** hosts with multiple GPU models can now be configured for passthrough individually in host config.
* **vGPU Support Without SR-IOV:** vGPU is now available through mediated devices for GPUs and hosts without SR-IOV enabled.
* **vGPU Live Migration and Advanced Flavor Configuration:** vGPU VMs can now live-migrate on Ubuntu 24.04 hosts. Flavors support advanced multi-vGPU profile selection across Ubuntu 22.04, Ubuntu 24.04, and Rocky Linux hosts.

#### Storage

* **External Key Management for Volume Encryption:** volume encryption is now supported with HashiCorp Vault as the external Key Management Service (KMS).
* **Volume Revert to Latest Snapshot:** volumes can now be reverted to their most recent snapshot directly from the UI as a fast, in-place operation.
* **NetApp Performance Tuning Parameters:** introduced new parameters (netapp\_performance\_cache\_expiry\_duration and netapp\_dedupe\_cache\_expiry\_duration) to fine-tune the frequency of querying performance and deduplication metrics.
* **Redesigned Volume Backend Configuration:** adding a volume backend is now a guided, multi-step experience. Search and select your storage array, provide only the required fields (pre-filled with verified defaults where available), and fine-tune optional settings as typed inputs. You can now remove any optional setting so it is excluded from the configuration and the backend default applies, and re-add it from Custom Key Value Configurations.

#### Networking

* **Simple (L2) Networking Reaches General Availability:** Simple (Layer 2) networking is now Generally Available.
  * **Native Simple (L2) Networking APIs:** the Networking and Compute Service APIs now natively recognize simple (Layer 2) networks, so ports no longer need to be pre-created before attaching them to a VM.
* **Networking Service Update**: updated the networking service to the 2025.2 (Flamingo) release.
* **Reassign Host Liveness Interface on In-Use Host Configs:** the interface used for Host Liveness Checks can now be reassigned to an existing interface on a host configuration that is already in use, instead of only to a newly added one.

#### Image Library

* [**Multiple Backend Stores for the Image Library**](https://docs.platform9.com/private-cloud-director/2026.8/images-and-image-library/image-library-multiple-storage-backends)**:** the Image Library can now be configured with more than one backend store, and the UI supports selecting a store when uploading or managing images.
* **Image Sharing Across Tenants, Including for Self-Service Users:** shared images can now be assigned to specific tenants from the UI, and self-service users can share their own images, not only administrators.
* **Image Upload from a URL:** users can upload an image from a URL without direct access to an Image Library host.

#### Identity

* [**Granular Role-Based Access Control (Beta)**](https://docs.platform9.com/private-cloud-director/2026.8/identity-and-multi-tenancy/rbac-roles-and-permissions/granular-rbac-roles)**:** six new roles, backed by a new policy engine, provide finer-grained delegation than the existing Admin, Self-Service User, and ReadOnly roles. Platform Admin and Service Provider Domain Admin apply platform-wide, Customer Domain Admin applies to a single domain, and Tenant Admin, Application User, and Tenant User apply to a single tenant.
* **SSO and Local Users Separated in Tenant and User Management:** SSO users now appear on their own tab, separate from local users, with SSO user management limited to quota changes.

#### Cluster Blueprint

* **Region-Specific DNS Domain Overrides:** cluster blueprints for multi-site regions can now override the DNS domain per site instead of enforcing a single domain across the entire region.

#### Kubernetes

* **Colocated Control Plane:** a cluster's Kubernetes control plane can now run on dedicated nodes in your own infrastructure instead of on the management plane, improving resilience for edge, large-scale, and proxied deployments.
* **Proxy Support for Kubernetes Clusters:** Colocated Control Plane clusters can now be deployed behind a proxy, and container image pulls during cluster creation honor the cluster's proxy settings.
* **Physical (Bare Metal) Kubernetes Nodes:** bare-metal hosts can now be registered directly as Kubernetes nodes, without virtualized provisioning, for both Managed and Colocated Control Plane clusters.
* **Kubernetes Version Support:** Kubernetes 1.34 and 1.35 are now supported for cluster creation and upgrade; support for Kubernetes 1.31 and 1.32 has been removed.
* **MetalLB Lifecycle Control:** the MetalLB add-on can now be enabled or disabled after a cluster is provisioned, instead of only at creation time.
* **Kubernetes Management Plane Status in `airctl`:** on self-hosted deployments, `airctl status` now reports the status of the Kubernetes management plane alongside other region components.
* **Clearer Error Reporting:** backend errors are now surfaced in the UI instead of failing silently.

#### Operations and Observability

* [**VM-to-Host Affinity for Stretched Clusters**](https://docs.platform9.com/private-cloud-director/2026.8/virtualized-clusters/stretched-clusters)**:** VMs can now be assigned soft or hard affinity to a host aggregate representing a failure domain, enabling a stretched-cluster deployment across two sites with automatic evacuation that respects site boundaries.
* [**API-Based Configuration of VM High Availability Response Modes (Beta)**](https://docs.platform9.com/private-cloud-director/2026.8/virtualized-clusters/virtualized-cluster/virtual-machine-high-availability-vm-ha#advanced-vm-ha-configuration)**:** VM High Availability now offers conservative, balanced, and aggressive response modes instead of a single fixed evacuation timing.
* [**API-Based Configuration of Storage Heartbeat for VM High Availability (Beta)**](https://docs.platform9.com/private-cloud-director/2026.8/virtualized-clusters/virtualized-cluster/virtual-machine-high-availability-vm-ha#configure-storage-heartbeat-for-vm-ha)**:** VM High Availability can now use an additional optional storage heartbeat over a shared NFS path, so a host is declared down only when both checks fail, reducing false positives from network glitches.
* **Component-Level Health Monitoring and Alerts:** etcd, management-plane, Kubernetes cluster, and node health are now continuously monitored with user-facing alerts when a component degrades.
* **Customer-Managed TLS Certificates for Self-Hosted Deployments:** a new `airctl provision-certs` command lets self-hosted deployments use a trusted certificate provider through cert-manager instead of the default self-signed certificate, and the certificate now survives upgrades.
* **Refreshed Table Header, Search, and Filter Interactions:** table headers, search bar interactions, and filter behavior have been redesigned across the UI, with a floating action bar that now appears on row selection.
* **Configurable Batch Action Bar Position:** the batch action bar includes a new toggle to choose a floating position (bottom-center, the default), pinned to the top of the table, or pinned to the bottom; the choice persists per user across sessions, and pinned positions no longer overlap the table header, rows, or toolbar.
* **Reorganized Navigation:** navigation has been reorganized, including moving Application Credentials under API Access.
* [**Terraform Provider (Beta)**](https://docs.platform9.com/private-cloud-director/2026.8/reference/terraform-provider)**:** a first-party Terraform provider, published on the public [Terraform Registry](https://registry.terraform.io/providers/platform9/pcd/latest) as `platform9/pcd`, lets you manage infrastructure as code across Identity, Compute, Networking, Persistent Storage, Image Library, load balancing, DNS, and key management, as well as cluster blueprints and host configuration and roles.

### Bug Fixes

#### Compute

* vGPU slices are now correctly passed to vGPU VMs on Ubuntu 24.04, restoring live migration for those VMs.
* vGPU VMs configured with SR-IOV virtual functions now survive a host reboot instead of going to an error state.
* VNC console access now works when only TLS encryption is configured, without a VNC password.
* The VM creation wizard now provides a Root Volume Size field when booting from an ISO image, replacing the fixed 50 GB root disk default.
* A VM's backing volume created from an ISO now uses the tenant's configured default volume type (for example, `vt-nfs`) instead of the generic `__DEFAULT__` type, so the Volumes list shows the correct type.
* A VM can now be deleted even when its host is offline or has been removed.

#### Storage

* Uploading an image to an encrypted volume with an NFS backend no longer fails.
* The VM snapshot deletion page now shows the current status of the related volume snapshot.
* Volume migration no longer fails with a state-change lock timeout during the final swap phase.
* Resolved multiple Storage Dashboard display issues: filtering, capacity labeling, and reconciliation between the dashboard and the Home screen now show consistent, accurately labeled values.
* Persistent Storage Service connectivity to a NetApp backend no longer fails in environments that route traffic through a proxy.
* A rare backlog in internal messaging traffic no longer triggers RabbitMQ disk alarms that could disrupt storage-service connectivity.
* The HPE storage driver now includes the latest upstream patches, preventing "LUN already exists" errors when creating a volume from an image.
* Volume list pagination no longer fails with a broken link error.
* The Persistent Storage Service now retries backend startup after a transient error instead of silently running with a backend missing.
* Resolved multiple volume management UI issues: custom properties now save on creation, image metadata can be removed, and successful deletes no longer report failure.
* Volume clone operations on NFS-backed storage no longer fail intermittently during concurrent file activity.

#### Networking

* Multiple simple (Layer 2) network interfaces are now displayed correctly under a VM's IP addresses.
* Changing the Geneve tunnel ID range in a blueprint no longer mislabels existing virtual networks as physical in the UI.
* Resolved a race condition during port creation that could leave a new tenant router unreachable from outside the virtual network.
* Self-service users can no longer create a physical network through the API, matching their intended permission scope.
* Resolved a rare deployment-time race condition that could leave the Networking Service unable to authenticate with the Compute Service, causing VM creation to time out.
* Resolved an issue where DNS zone pool configuration updates could fail due to a credential-service lookup error.
* VM restore through Commvault now works correctly with simple (Layer 2) networks.
* Custom network-type settings configured before an upgrade are no longer reset to their defaults afterward.
* Resolved an issue where networking services could remain unhealthy in some regions after an upgrade.
* Resolved an issue where a stale router port could remain in the networking database and block automatic cleanup.
* Cross-tenant network quota lookups no longer fail with a server error.
* VM creation and cloning now use the specific network port or private IP address you select, instead of assigning a different one automatically.
* Resolved multiple Networking Service worker-process stability issues under load, including workers that stopped recovering after a forced restart.
* In the host management console, outbound proxy changes now apply to package-manager settings, and DNS server entries no longer block bond creation.

#### Image Library

* Resolved image upload failures and incorrect status reporting for zero-byte images.
* Resolved a security issue (CVE-2026-34881) where a tenant user could abuse image import to reach internal network resources, including the cloud metadata endpoint.

#### Identity

* Resolved a security issue (CVE-2026-33551) where a restricted application credential could be used to create EC2 credentials carrying the parent user's full role set.
* Authentication tokens are no longer written in full to system logs, reducing the risk of token exposure.
* User sessions no longer expire abruptly after repeated login and logout actions.
* Application credentials for SSO users no longer stop working roughly 24 hours after the last SSO login.
* Resolved multiple SSO reliability issues: deleting an SSO group no longer blocks subsequent logins, and Tenants and Users data now loads correctly after SSO login.

#### Cluster Blueprint

* Cluster blueprints now correctly persist the shared file system setting for Image Library storage.
* A cluster blueprint's volume backend name can no longer be changed once volume types are defined against it, preventing broken provisioning.

#### Kubernetes

* Removing a rule from a cluster's exposed load balancer ports now also removes it from the worker nodes' security group.
* Kubernetes cluster creation no longer stalls indefinitely in single-region Community Edition deployments.
* A single tenant reconciliation failure no longer blocks synchronization of the remaining tenants.
* `airctl upgrade --k8s-only` no longer fails with a JSON parsing error caused by Kubernetes configuration file permission warnings.

#### Operations and Observability

* Self-hosted management-node log files are now rotated and size-limited, preventing disk exhaustion that could previously cascade into a management-plane outage.
* Audit log queries in the UI now use the correct time window regardless of browser timezone.
* VM High Availability no longer incorrectly pauses VMs on the surviving host of a 2-node cluster when the other node goes down.
* Resolved a certificate validation failure that could prevent VM High Availability from tracking volume attachment state in self-hosted deployments using custom certificates.
* Self-hosted UI login no longer fails when the node hosting the active ingress connection goes down.
* Kubernetes cluster creation for self-hosted on-prem deployments no longer stalls due to a missing cleanup-job container image.
* Host upgrades no longer fail when a region contains an empty cluster, which previously could strand hosts on an older version and disrupt VM connectivity.
* `pcdctl decommission-node` no longer removes shared Image Library storage that other hosts still depend on.
* `pcdctl decommission-node` no longer gets stuck while removing OVS bridges.
* Resolved multiple issues where Dynamic Resource Rebalancing failed to evacuate VMs when configured CPU or memory utilization thresholds were exceeded.
* Restoring an air-gapped self-hosted deployment to a fresh cluster no longer fails with a certificate authority mismatch.
* The Prometheus metrics query endpoint now requires a valid Identity Service authentication token; previously it could be queried without authentication.

### **Known Issues**

* SSO Login Failure in Multi-Region Deployments During Partial Upgrade
  * As part of critical SOC 2 and data security enhancements, single sign-on (SSO) redirects now use hash parameters instead of query parameters to prevent token leaks in logs. This change introduces a backward compatibility constraint during phased updates. If the Infrastructure region is upgraded to the August release while secondary regions remain on an earlier version, SSO authentication will fail because legacy UI versions cannot process hash parameters.
  * Workaround / Resolution: All Infrastructure and secondary regions must be upgraded to the August release simultaneously. Partial or regional phased upgrades are not supported for this release.
* In some environments, OVN logical switch port backing the metadata network has its type set to an empty value instead of `localport`, preventing VMs from reaching the metadata service during cloud-init. To resolve this, please contact Platform9 Support for assistance.
* Enabling memory hot plug on Windows VMs causes continuous memory growth on the host until it reaches the hotplug max memory. Affects Windows Server 2019 and 2022. It is recommended to set a conservative maximum memory value.
* Hotplug-enabled Windows 11 VMs may report the `HOTPLUG_MEMORY_MAX` value as the active memory before the first reboot, rather than the configured `HOTPLUG_MEMORY` value. Rebooting the VM corrects the reported memory value.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.platform9.com/release-notes/august-2026-release.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
