Changelog
Last updated: October 2026
Asternodis updates in place from the controller UI: it checks for a release, verifies its signature, and swaps the binary. Below is what each release changed.
v1.0.23
current 1 October 2026- Added Thick-LVM VMs (including LVM on an iSCSI LUN, block storage with no native snapshot) can now fail back in place, and incrementally. A guest that has been running at the recovery site returns home by shipping only the blocks that changed there, in seconds, and keeps its recovery points, instead of re-copying the whole disk. Proven on a live two-site iSCSI deployment. (A thick volume group shared across a whole cluster is the one shape still refused: such a guest comes home with Abort failover, which reverts it to its pre-failover disk. See the storage matrix.)
- Added The asternodis dr command line now prints the full go/no-go preflight before a failover, exactly as the web UI does, and gains verify-release (check a download's signature by hand) and audit verify (check the tamper-evident audit log from the shell, with no running controller). One release verifier now backs the in-app updater, the install and update scripts, and the CLI alike.
- Added Every release is verified against its Ed25519 signature before it is installed: in the controller's in-app updater, in install.sh and update.sh, and in the pipeline before a release or this site is published. A download that does not verify is refused, not installed.
- Added The continuous integrity scrub now covers every recovery copy on its own terms: ZFS, Ceph/RBD and container points are chain-verified and capture-checked, while directory, NFS, CIFS and LVM-thin points are measured by digest against what changed since capture. The coverage panel shows whether each lane is keeping up, and an admin can set the read rate.
- Changed In-place failback for home disks that are not ZFS (LVM-thin, Ceph/RBD, a directory/NFS/CIFS file store, and now thick LVM) is on by default, rather than a switch you had to turn on first. It stays labelled experimental and can still be switched off per site.
- Changed New recovery points are application-consistent by default, with a per-guest opt-out: the guest is quiesced around each capture wherever its agent (for a VM) or the host's freezer (for a container) allows it. Containers freeze with the cgroup freezer once around every volume, and a consistency group captures its containers before it freezes any VM. A site that was capturing crash-consistent gets a day's notice before the new default takes effect.
- Changed The failover preflight validates the recovery network per guest on real evidence: a target bridge that does not exist on the node that will run the guest, an Open vSwitch bridge included, is now a definite failure rather than an unverified maybe. A preflight that fails never blocks recovery; you acknowledge it first. It now runs on every route: one guest, a recovery plan, a whole site, a planned move, and the asternodis dr failover command.
- Changed Business licences carry a pooled protected-node allowance alongside DR Site Pairs, shown to operators and admins and enforced when you enrol a guest on a new node. A paid licence keeps running through a licensing-service outage (validated offline against a signed token, with its paid-through and last-validated dates on the License page, and read without ever touching the network). Deleting every pair no longer restarts the 14-day trial clock.
- Fixed More failback paths that could have quietly cost a guest its recovery points now keep them: a fast-baseline failback re-ships and re-verifies any range the reverse cycles did not land before it will give a disk up for a whole-disk rebuild, a file-home failback repairs a divergence by copying only the differing ranges, and an aborted fast-baseline failover no longer restarts the source in the way that used to destroy them. Every reverse cycle records whether its data landed, so a torn cycle heals on the next failback instead of being adopted.
- Fixed A continued sweep of readings that were shown as a definite answer when they could not actually be taken: an unreadable storage, cluster, port or recovery point reported as clean, empty or healthy. A check that cannot look now says so, everywhere the last sweep had not yet reached.
- Fixed The pre-boot self-heal reaches guests it used to miss: FAT, btrfs, NTFS and LVM volumes it could not see, and a recovered UEFI guest whose boot entries did not travel (which used to stop at "No bootable option"). It never hard-stops a Windows guest in the middle of a chkdsk it scheduled, and its tooling is installed within bounds, never by a path that could reach the host's bootloader.
- Fixed Restore in place keeps the guest's recovery points (at this site and at every other site a fan-out restore reaches) and keeps the stale pre-restore tip out of every reader, so the points it preserved can still be failed over to.
- Fixed Alert accuracy: a node that is powered off is no longer dialled like a blocked firewall and raised as critical, a closed port that nothing on the pair dials is no longer a "data path blocked" alarm, and the daily port sweep no longer clears an alert that a wider check had raised.
v1.0.22
24 September 2026- Added A guest whose recovery copy is a qcow2 file (a directory, NFS or CephFS shadow) now keeps its retained recovery points through an in-place failback: the failback ships only the failover delta into the file and verifies it, and forward replication resumes incrementally, exactly as it already did for ZFS, LVM-thin and Ceph copies.
- Added Shadows lists a guest's own disks that its configuration no longer references anywhere (not attached, not unused, not under a snapshot) as orphaned disks with a Delete that re-checks the configuration on the node first. A running Prepare move can be stopped from its operation page; the guest returns to service at its source.
- Changed Compliance shows retired-plan evidence from both sites, each row naming the site that holds it. Every failover, DR test and failback log says what it decided about re-addressing (which re-IP it applied or reverted, or why none applied), and a pair default that could not be read is a warning naming the remedy.
- Changed The Shadows page decides in-use / deletable from the live state on every listing, a stopped DR test or a reaped DR copy leaves the list at once, and a retained recovery point's row names its snapshot so it cannot be read as the volume it hangs off. Recovery points a batch delete is removing read "deleting…" while it runs.
- Fixed Deleting a base recovery-copy volume on the Shadows page now says, before you confirm, that it also removes the retained recovery points taken from it: the points are snapshots of that volume and cannot outlive it. The batch delete warns about points that go with a selected base but were not themselves selected, and the unprotect flow already disclosed this. Delete individual point rows to prune while keeping the base copy.
- Fixed A DR test whose copy was still being built could lose its handle to the background reconciler and come up with no Stop control; the Compliance report's cross-site merge matched plans by a per-site id and could drop or duplicate a site's own retained test evidence when a plan name had been reused across cycles; a guest's retained recovery points stayed unlisted on Shadows for a scan cycle after it was unprotected; and a batch delete kept refusing re-protection for minutes after the volumes were gone.
- Fixed When a fast-baseline failback finds a range the reverse cycles did not land on the primary, it now re-ships everything written since the failover through the same lane and verifies again before giving the disk up for a whole-disk rebuild. The guest keeps its recovery points. Every reverse cycle records whether its data landed.
- Fixed A failback's verify now reads the primary's disk three ways and refuses only with evidence per range; a stalled record read no longer lets the old-home and orphan-disk deletes treat a failback's freshly seeded disks as leftovers; one guest's move steps run one at a time so stopping a prepare cannot race the quiesce it is undoing; and the failback confirm says what withdrew a fast reverse baseline instead of blaming the failover-time quiesce.
- Added A recovered guest with no working guest agent gets one installed before it boots (Linux by default, Windows with the guest tools now shipped inside Asternodis), so a crash-consistent capture comes up application-consistent. A new Install guest agent action does the same for a guest at its home site, live over SSH or with one restart. Off-switch in Settings.
- Added Recovery points on a directory, NFS or CIFS replica get the same filesystem check, repair and pre-boot self-heal as points on ZFS, LVM-thin and Ceph. Repair now runs the repairing check on a disposable copy of a point, so a standing filesystem warning can be proven or cleared without a recovery.
- Added An alert when the link to the paired site is degraded or unreachable. It clears itself when the site answers again.
- Added The change-rate anomaly review shows the evidence behind a flag (what a guest shipped against its free space), and a guest with a known benign pattern can be exempted, with a reason. A guest resumed after a pause is no longer tripped again by its own catch-up cycle, a full reseed is never mistaken for a spike, and the run history says which runs were full seeds.
- Changed The Replication page's alert banner is collapsed to a count by default and shows only the alerts that mean a recovery would not work. Every status chip now says what it means and what to do about it.
- Changed The Overview's Copies held here panel splits "points checked" into two figures (filesystem-checked and content-hashed) because the fast check could read 100% while the slow one had barely started.
- Changed Operations shows an amber Partial outcome for a run that finished but left something behind, instead of the same green tick as a clean run, and the audit log records what an operation did on every route, with the guest and the operation named.
- Changed Failback to a chosen node says what it costs before you confirm (a full copy onto fresh disks, and the guest's retained recovery points with it) on every surface that offers it. The old home's disks are listed on Shadows as reclaimable, and the guest's page offers to reclaim them.
- Fixed Many readings that could not be taken were shown as a definite answer: an unreadable storage, cluster or listing came back as empty, clean or zero. Fixed throughout: a check that could not look now says so, and the Shadows scan names the storages it could not read instead of reporting them clean. That includes a Ceph pool attached without a local Ceph config, which no sweep had ever reached.
- Fixed Three paths could destroy data without saying so (a planned move that left two live writers on one disk, an orphan sweep that removed a shadow something was still serving, and a seed that overwrote or promoted a torn shadow), and a background cleanup could destroy a running guest with no ownership check. All four are gone; qcow2 shadows are no longer touched until their writer has provably exited.
- Fixed A momentary SSH refusal no longer costs a whole failback, a slow recovery site no longer forces a stopped guest into a full reseed, and a return-sync cut short heals itself on the next failback instead of stranding the guest.
- Fixed UEFI variables and vTPM state: a firmware disk captured on LVM-thin now restores into a ZFS recovery copy (it used to fail on the padding and boot the guest on default firmware), a failed restore names the step that failed, and the cloud-init drive returns to the slot it was captured on instead of reading as a newly added, unprotected disk.
- Fixed The recoverability badge read "Recoverable" through eight conditions that mean it is not; each now shows a distinct at-risk status. The failback-to-node picker answers in a third of the time, and its leftover-disks card says when it could not check rather than looking clear.
- Fixed Deleting a DR Site Pair now removes its TLS certificate and encryption key with it, and an offline edit of a Windows copy fails honestly on a hibernated or BitLocker volume instead of corrupting it.
v1.0.21
19 September 2026- Added Restore in place: roll a guest back to an earlier recovery point on the primary itself, without failing over. One operation and one short outage instead of a site change and a failback, and it is the recommended answer when a change-rate anomaly fires. VMs on every supported home storage, now including directory, NFS and CIFS.
- Added An Alerts page. Every alert names its guest, says what it means and links to the page where you act on it, with silencing for the ones you have judged and a one-click dismiss for a whole firing set.
- Added A change-rate anomaly now holds the recovery site as well as the source: no new recovery point is captured from the suspect state, and nothing older than the detection can age out of the retention schedule while the anomaly is under review.
- Changed Settings gathers what were five separate pages into one tabbed page, and Shadows replaces its guest dropdown with a flat, searchable list.
- Fixed Compliance and License were reachable only by an admin, so the people who need the evidence could not open it.
- Fixed The control-coverage export wrote an empty file once a recovery plan had been retired, and the audit-log export stopped at 5,000 entries without saying so.
- Fixed The integrity scrub held an interlock that stopped a guest replicating for as long as the check ran, up to tens of minutes on a large guest. It now reads from its own isolated copy and never pauses replication.
- Fixed A verification that found damage was recorded as a clean success, so the one query that would find damaged points returned none of them.
- Fixed Rolling back a prepared cross-site migration destroyed the guest's recovery points while reporting that nothing was lost.
- Fixed The primary site's audit log recorded no failover at all.
v1.0.20
16 September 2026- Added Licensing scales on protected Proxmox nodes as well as DR Site Pairs. Home Lab is uncapped on nodes.
- Added A DR test now records which recovery point each guest booted from, so the evidence says what was actually proven.
- Fixed A dropped SSH session during failback could strand a guest at home, unprotected, with both recovery paths refusing each other.
- Fixed A failed migration prepare could leave the production guest powered off, and a re-seed could destroy every recovery point without saying so.
- Fixed A shadow sweep that was cancelled or cut short recorded itself as a complete inventory.
- Fixed Container failback transports failed silently and without retry; they now report and retry.
- Fixed An interrupted destroy could lock a guest against ever being destroyed again.
v1.0.19
10 September 2026- Added DR-test evidence is mapped to the control frameworks people are actually audited against: NIST SP 800-53, ISO/IEC 27001, NIS2 and BSI IT-Grundschutz.
- Added The recovery site gets its own protection view and the same charts as the primary, instead of reporting "0 protected".
- Added The dashboard shows DR posture, not just infrastructure.
- Fixed A guest whose volumes share a name now replicates every disk rather than one.
- Fixed An unknown guest type no longer reads as "VM" on the failover form.
v1.0.18
9 September 2026- Added Multi-site topologies (hub, DRaaS, mesh and fan-out) are reachable in the product, not just described in the docs.
- Changed Abort now checks the primary will start the guest before it stops the DR copy, rather than the other way round.
- Changed Deleting a DR copy states what it takes with it, and several destructive paths refuse before destroying rather than reporting afterwards.
- Fixed A replication cycle is stood down before anything destroys its shadow; cancelling a cycle no longer relaunched it into its own teardown.
- Fixed A guest that was never seeded now raises an alert instead of reading as healthy.
- Fixed A peer-refused DR operation is audited as refused, not as successful.
v1.0.17
3 September 2026- Added Failback to a chosen node, for when the original home node is not the right destination.
- Fixed Thawing a guest reported success for a thaw that never happened.
- Fixed Alert accuracy and unprotect behaviour across several paths.
Releases before v1.0.17 were pre-release development and are not itemised here. Update in place from Settings, or see the install guide.