Stateless operation: the config lives on the pools
In 6.0 a RAM-booted node started empty, and you restored its configuration by hand. In 6.2 OviOS
saves its configuration automatically to a hidden dataset on every managed pool,
<pool>/.ovios-system/<node-id>.
At boot it imports the pools, picks the newest valid generation and applies it before the storage
services start. That covers iSCSI targets, NFS exports, SMB shares and options.
Two ways to run stateless
Kernel command line: add ovios.autorestore=1
to the boot entry. Every configuration change is saved as a new snapshot generation on every pool, and the
last 10 are kept. The newest valid generation is restored at boot. This is the recommended mode for USB, ISO
and PXE deployments.
Options only: options auto.restore.enable on
restores at boot from the newest sync-config bo
archive, found in the osbackup dataset on
system.backup.pool or in
/tmp/osbackup. This mode needs no change to the boot entry.
| Area | 6.0 | 6.2 |
|---|---|---|
| RAM / Live OS boot | Starts with a factory configuration; restore manually | Configuration restored automatically before services start |
| Where config is kept | System disk and optional backup archives | A copy on every managed pool, with 10 snapshot generations and a manifest |
| Node identity | Tied to the installed system | Hardware DMI UUID, so the same machine finds its own config on shared pools |
| ZFS hostid | Random per install; copied by config sync | Derived from the DMI UUID and stable across reboots; never replicated to partners |
| Restore safety | Archive extracted as-is | Allow-listed paths, a checksum-verified manifest, and a config-version marker that logs restores from older or newer releases |
| Status | — | sync-config persist-status lists generations per pool |
New option: smb.secrets.restore
This option decides whether SMB secrets travel with the saved configuration. Those secrets are the
Samba password database, machine secrets and the AD keytab. With it on, SMB users
and the domain join survive a stateless reboot. With it off (the default), they are
never written to the pools. After a full restore you re-create SMB passwords with
smb-user and re-join the domain with smb-join. System accounts, CHAP
secrets and the web password are always saved.
Boot options
ovios.autorestore=1 enables restore at boot. ovios.autorestore.force=1
restores even when the node already has local config. ovios.autorestore.anynode=1
adopts another node's config when the hardware UUID has changed. spl.spl_hostid is
no longer required.
Run mode everywhere
The version command, the login banner, the web dashboard and the PDF report all show
the same version and say whether the node runs live or installed, stateless or stateful.
Full details, including what is saved, the secrets policy, all boot options and troubleshooting, are in the Live-OS & Stateless Guide.
New Features & Capabilities
The following capabilities are new since 6.0.
iSCSI CHAP Authentication
A new target chap menu adds or removes incoming, outgoing and mutual CHAP per target,
with masked password prompts. Secrets are kept in /etc/tgt/chap.secrets (mode 0600,
written atomically), and targets.conf only names the users. Secrets never appear on a
command line or in verbose output.
Thin LUNs with Discard / UNMAP
LUNs created as thin now support SCSI UNMAP; the ovios-shell enables it automatically
(a thin LUN can be opted out with the ovios:thin_provisioning=off ZFS property, then unmapped and re-mapped). When a client deletes data and issues
discard/UNMAP (Linux fstrim, Windows ReTrim, VMware VMFS6 space reclamation), the freed
blocks go back to the ZFS pool. How to use it.
target bind / unbind
Restrict a target to specific initiator addresses or IQNs, or open it up again, without re-creating it.
Guided S3 Setup
options s3.enable on walks you through the data volume, credentials and certificates.
If you cancel or the setup fails, the option stays off and nothing half-configured is left
running. The S3 console has its own s3.ui.enable option.
S3 Guide.
Storage Report & Backups
A one-click PDF health report covers pools, disks, LUNs, shares and ARC, with findings.
sync-config list-backups and sync-config restore let you pick and
restore any archive from the shell.
Shell Improvements
options is built into the shell with tab completion. Also new:
service reset, service <name> logs, passwd,
scanbus, InfiniBand verbs tools (ibv), pool list short
output, and lun create pool/lun.
Pool Import Control
The new import.src option chooses whether pools are imported by scanning devices
(default) or from the cache file. Imports are safer: disk wiping and device resolution are now
checked before anything is written.
Web Interface
Served over HTTPS with a self-signed certificate. The dashboard page is built into the binary, so upgrades never break reboot or shutdown. Action errors are shown instead of silently ignored, and the version is displayed.
Fixes & Hardening
| Area | Problem in 6.0 | 6.2 |
|---|---|---|
| Config sync | Concurrent syncs could clobber each other; a LUN map could push an empty targets.conf to partners | Atomic targets.conf writes, serialised syncs, and the hostid is no longer replicated |
| Snapshots / volumes / LUNs | Edge cases could lose data or break restore | Safer snapshot restore, clone and delete paths |
| Pools | Disk wipe and device resolution could pick the wrong device | Explicit by-id resolution and checks before wiping |
| Web security | Command injection, missing CSRF protection, XSS, and a concurrent-map crash | All fixed. API calls with curl keep working. |
| Services | Failed starts gave little information; multipath service issues | Failures point to service <name> logs; multipath fixed |
| Audit | auditd failed on overlay (live) root filesystems | Enabling is handled correctly on overlayfs |
| Versioning & licence | Version strings differed between components | One version source (VERSION file + git commit); unified OviOS Software EULA v2.0 |
Upgrade Notes
For stateless boot, set skip.import
to off. Autorestore can only find saved generations on pools it is allowed to import.
After upgrading, make one configuration change (or run sync-config persist)
so the first generation is written. Then check it with sync-config persist-status.
- ZFS pool data is untouched
- Existing 6.0 backup archives can be restored
- iSCSI targets & LUN mappings
- NFS and SMB share definitions
- All 6.0 options keep their values
- New smb.secrets.restore option is off by default
- An existing spl.spl_hostid boot option is still honoured
- Wizards and commands unchanged
- Rolling live upgrades, installed or live OS
Using Active Directory or local SMB users on a stateless node? Decide on
smb.secrets.restore before your first reboot. Turn it
on to carry passwords and the domain join on the pools. Leave it off if those secrets must never
leave the node. In that case, plan to run smb-user and
smb-join after each full restore.