v0.3.0-alpha.2 — Pluggable storage + vendor-agnostic iSCSI
Pre-releasev0.3.0-alpha.2 — Pluggable storage, vendor-agnostic iSCSI
This is the storage release. Backends are now mix-and-match from a single Add Backend UI, and the new iscsi_lvm backend turns any iSCSI target into a vendor-agnostic per-VM block-device pool — Proxmox-equivalent, no per-vendor REST adapter required.
Status: Alpha. Verified end-to-end via a 23-assertion integration suite running inside a fresh KubeVirt VM against a live LIO iSCSI target. See
infra/test/HANDOFF.md.
Highlights
iscsi_lvm storage backend
Vendor-agnostic auto-provisioning of per-VM block devices on top of any iSCSI target. Mirrors Proxmox VE's LVM-on-iSCSI mode:
- Operator carves one big LUN on any iSCSI array (TrueNAS, Pure, Synology, plain Linux LIO, …).
- Click Add Backend → iSCSI + LVM in the UI, fill portal + IQN + VG name.
- Click Initialize Volume Group → type-to-confirm dialog → agent runs
pvcreate+vgcreateonce. - Every subsequent VM-create allocates its own
lvcreateslice.lvchange -aeyexclusive activation gates per-VM access — safe foundation for live migration when you go multi-host.
No per-vendor adapters. No REST keys. Add a SAN to the UI and N VMs auto-provision their own disks on it.
NFS auto-mount via the agent
Manager runs unprivileged. The agent (which has root) handles mount.nfs over /v1/storage/nfs/*. Operators don't SSH the host to mount NFS exports — they fill the form, click Add, the manager probes and reports success/failure right there.
Live registry — no manager restart
Add or delete a backend through the UI and it's immediately usable for VM-create. The previous behavior (TOML-only registry, restart required) is gone. UI-sourced backends are tracked separately (storage_backend.source = 'ui') so the startup TOML reconciler doesn't sweep them away.
Tiered backend kind dropdown
Three recommended kinds shown by default in Add Backend: local_file, nfs, iscsi_lvm. Vendor-specific or operationally heavyweight kinds (iscsi generic, truenas_iscsi, spdk_lvol) tucked behind a Show advanced kinds disclosure. Default selection is local_file (zero-deps).
Platform auto-update
Settings → Updates lets admins upload .nqupdate bundles or enable internet checks against a manifest URL. Apply order is manager → agents (rolling) → UI; running VMs are not disturbed by agent restart. Binaries land at /opt/nqrust/bin/<name>.<version> with a <name> symlink for atomic swap.
What changed since v0.2.3
Added
- Storage backends:
iscsi_lvm,nfs(auto-mount), platform auto-update. ControlPlaneBackendtrait gainsprobe(),host_path_for(),activate_volume(),deactivate_volume()(default no-ops;iscsi_lvmoverrides).POST /v1/storage_backends/:id/initializewith destructive-confirmation flow.- Migration
0037_storage_backend_source.sql+0038_iscsi_lvm_backend.sql. - VM lifecycle hooks:
activate_volumebefore Firecracker spawn,deactivate_volumeafter stop. - Host package dependencies expanded — installer + air-gapped bundle now ship
open-iscsi,lvm2,qemu-utils,nfs-common.iscsidenabled automatically post-install. infra/test/iscsi-alpha-{vm.yaml,install.sh,runner.sh,HANDOFF.md}— full KubeVirt-based integration suite (23/23 passing on this release).
Fixed (alpha.2 vs alpha.1)
ensure_volume_registeredwas failing on block-device rootfs paths (fs::metadatareturns 0, violatedpositive_size); deactivate hooks never fired on stop. Volume attachment now goes throughprovision_rootfs's structured handle (98c99a6).restart_vmrejected/dev/<vg>/<lv>paths becauseensure_allowed_pathonly permittedMANAGER_IMAGE_ROOT/MANAGER_STORAGE_ROOT. Backend-resolved device paths now bypass it (49eb4a7).
Changed
- Manager + agent installed under
/opt/nqrust/bin/<name>.<version>with symlink (auto-update layout). - systemd units set
RestartForceExitStatus=42so a clean self-update exit triggers restart on the new binary.
Install
The release ships software artifacts only — kernel + rootfs come from v0.2.3 (the install script handles fallback transparently):
# Online install (recommended)
curl -fsSL https://github.com/NexusQuantum/NQRust-MicroVM/releases/latest/download/install.sh | sudo bashOr use the test harness directly (in a fresh KubeVirt / cloud-init VM):
curl -fsSL https://raw.githubusercontent.com/NexusQuantum/NQRust-MicroVM/main/infra/test/iscsi-alpha-install.sh | VERSION=v0.3.0-alpha.2 sudo bashTest result
T1 Backend create + duplicate-name ✅ 2/2
T2 Validation rejects missing fields ✅ 3/3
T3 Initialize VG + idempotent + verified ✅ 6/6
T4 Wrong-kind initialize → 409 ✅ 1/1
T5 VM lifecycle on iscsi_lvm ✅ 8/8
T6 Live registry + volume protection ✅ 3/3
23/23 against released musl artifact
Detailed walkthrough: docs/runbooks/iscsi-lvm-troubleshooting.md · infra/test/HANDOFF.md
Known caveats
- Single-host data plane only:
clone_from_imagewrites the initial rootfs from the manager's local/srv/images. For genuine multi-host clusters the agent on a different machine wouldn't see the manager's local image; track for the multi-host data-plane delegation follow-up. - No image artifacts in this release: kernel + rootfs unchanged since v0.2.3, install scripts pull them from there. Fresh stable will reship them.