2026.2 Series Release Notes

18.0.0

New Features

  • Adds support for updating the start and end dates of a lease with flavor:instance reservations.

Upgrade Notes

  • blazar-manager no longer creates database tables at startup. The database schema is now managed exclusively by Alembic migrations. Operators must run blazar-db-manage --config-file <conf> upgrade head before starting blazar-manager on a new deployment (as is already done for DevStack-based installs). Existing deployments are unaffected.

Security Issues

  • Fixed two security flaws with the v2 API: any user could update/delete a lease from any project via the v2 API, provided that they had the lease ID. Additionally, any user could use the v2 API to list all leases, including those in another project. LP#2162719

    Operators that cannot yet upgrade should consider instead disabling the v2 API with the following config in blazar.conf:

    [api]
    api_v2_controllers =
    

Bug Fixes

  • Fix deletion of host extra capabilities. Specifying a value of None (null in JSON) when updating host capabilities will now remove the capability. LP#1674524

  • Removed the implicit db_api.setup_db() call from blazar-manager, which could race with Alembic migrations during deploys or restarts and leave the database in an inconsistent state.