Skip to content

OpenNebula

Summary

OpenNebula is an open-source cloud management platform for building private, hybrid, edge and sovereign clouds on KVM virtual machines and LXC system containers. One central daemon (oned) on a front-end drives hypervisors, storage and networks through pluggable drivers, which makes it much simpler to run than OpenStack. The current release is 7.4 "Helix" (7.4.1, 2026-09-10). Recent releases added a gRPC API, the OneDRS load balancer, OneKS managed Kubernetes, NVIDIA AI-factory integrations and VMware migration tooling. The Community Edition is Apache 2.0; the Enterprise Edition is a subscription from OpenNebula Systems (Spain), which is a core partner in the EU's IPCEI-CIS sovereign-cloud programme.

Key Facts

Attribute Detail
Latest Version 7.4.1 (2026-09-10); 7.4.0 "Helix" released 2026-07-27
Previous minor 7.2 "Dark Horse" (7.2.0 on 2026-04-07, 7.2.1 EE on 2026-05-21)
Release cadence Minor release about every 6 months; EE STS support 9 months, LTS at least 36 months
License Community Edition: Apache 2.0. Enterprise Edition packages: commercial terms with a subscription
Developer OpenNebula Systems (Madrid, Spain) plus community
Repository github.com/OpenNebula/one
Language C++ (oned), Ruby (drivers, CLI, OneFlow), JavaScript/Node.js (FireEdge / Sunstone)
Hypervisors KVM (primary) and LXC. Firecracker and LXD removed in 6.10; vCenter removed in 7.0
APIs XML-RPC (:2633), gRPC (:2634, since 7.2), REST for OneFlow, OneGate, OneForm and OneKS
Certified scale 500 hypervisors per oned instance (users report ~2,000); federation beyond that
Front-end OS (7.4) RHEL/AlmaLinux/Rocky 9-10, Ubuntu 24.04/26.04, Debian 12/13, SLES 15, openSUSE 16
Stars ~1.5k (recorded by 2026-08)

Overview

OpenNebula manages virtualized data centers as a cloud: users and groups get quotas and self-service through the Sunstone portal or APIs, while administrators organize hosts into clusters, virtual data centers (VDCs) and federated zones. Its main selling points are operational simplicity (one daemon, one database, one log), a wide choice of storage and network backends, and an edge-first model where many small clusters (on-premises, bare-metal providers or public clouds) are provisioned and managed from one front-end. Since 2024 the project has positioned itself as a VMware replacement (OneSwap migration, OneDRS) and as a platform for sovereign "AI factories" with NVIDIA GPU fabrics.

The component diagram shows the main pieces of a 7.4 deployment.

flowchart LR
    subgraph FE["Front-end"]
        SUN["Sunstone (FireEdge :2616)"]
        ONED["oned<br/>XML-RPC :2633 / gRPC :2634"]
        DB[("SQLite or MySQL")]
        SCH["Scheduler: rank + OneDRS"]
        SVC["OneFlow, OneGate,<br/>OneForm, OneKS"]
    end
    subgraph C1["Cluster (on-prem or edge)"]
        KVM["KVM hosts (libvirt)"]
        LXC["LXC hosts"]
        DS["Datastores: Ceph, NFS,<br/>local, LVM SAN, NetApp"]
        NET["VNets: bridge, VLAN,<br/>VXLAN, OVS"]
    end
    SUN --> ONED
    SVC --> ONED
    ONED --> DB
    SCH --> ONED
    ONED -->|"drivers over SSH"| KVM
    ONED -->|"drivers over SSH"| LXC
    KVM --> DS
    KVM --> NET

Internals are covered in Explanation.

Release Highlights

7.4 "Helix" (July 2026)

  • Fully redesigned Sunstone interface (same concepts and workflows, new layout).
  • OneKS Elastic Kubernetes as a Service and LVM SAN storage move from EE to the Community Edition.
  • NVIDIA Infra Controller (NICo) integration for AI-factory-scale bare metal as a service (EE).
  • OpenNebula Backup Exporter (OneBEX) for third-party backup pulls of qcow2 and LVM disks; Veeam no longer needs a separate backup-server VM; Restic S3 backend; selected-disk backups.
  • OneDRS storage migrations; OneSwap batch VMware migration; VLAN delegation rules for tenants; SR-IOV switchdev with OVS; Ubuntu 26.04 and Rocky Linux packages.

7.2 "Dark Horse" (April 2026)

  • gRPC API (Protocol Buffers over HTTP/2) next to XML-RPC; official test shows 2-3x faster responses under load.
  • NVIDIA Fabric Manager (NVLink/NVSwitch, EE), Grace Blackwell GB200/GB300 validation, Spectrum-X, BlueField DPUs.
  • Live storage migration between LVM and file datastores; redesigned LVM subsystem with thin provisioning (EE in 7.2); Pure Storage FlashArray driver; NetApp incremental backups; VirtioFS datastores.
  • VM memory encryption, vTPM, enforced Sunstone 2FA, one.vm.exec API to run commands in guests.
  • OneForm automated cluster provisioning on-premises and on cloud or bare-metal providers.

7.0 "Phoenix" (July 2025)

  • New scheduler framework with OneDRS (ILP-based load balancing with usage forecasts).
  • Removed Ruby Sunstone, vCenter drivers, ebtables driver and legacy ec2/azure hybrid drivers; migration tools (onedb, onecfg) added to CE.

The full release table is in Reference: Release History.

Editions, Licensing and Pricing

Edition What you get
Community (CE) Full platform under Apache 2.0, public package repositories, community forum support
Enterprise (EE) Subscription: EE packages with extra fixes, maintenance releases every ~3 months, STS/LTS lifecycle, SLA support, EE-only integrations (e.g. NVIDIA Fabric Manager, NICo, Veeam, NetApp)

Subscriptions come in Elemental, Standard and Premium tiers, priced as a base fee plus a per-node fee. The third-party tracker SpotSaaS (2026) lists USD 3,750/yr + USD 375 per managed node (Elemental), USD 8,750/yr + USD 875 per node (Standard) and USD 13,750/yr + USD 1,375 per node (Premium). OpenNebula quotes current prices on its subscriptions page. Details: Reference: Editions and Subscription Pricing.

Features move to CE over time

Restic backups and Prometheus monitoring moved to CE in 6.10; LVM SAN and OneKS moved in 7.4. Check the "(EE)" markers in each release's What's New before planning.

Evaluation

  • Why it is better: One daemon and one database instead of dozens of services, so deployment takes hours and troubleshooting starts in oned.log. KVM and LXC are managed together. It is edge-native (OneForm provisions remote clusters) and has built-in VMware exit tooling (OneSwap, OneDRS) plus NVIDIA GPU fabric orchestration.
  • When it fits:
    • VMware replacement after the Broadcom licensing changes
    • SMB to mid-size private clouds that need self-service and multi-tenancy
    • Distributed edge or multi-site clouds managed from one place
    • GPU and AI factories (NVLink/NVSwitch, Grace Blackwell, Slurm appliance)
    • Sovereign and public-sector clouds in Europe, research institutions, managed service providers
  • When it does not fit: Very large multi-tenant public-cloud-style IaaS with many independent service teams (OpenStack is stronger), or pure container platforms (use Kubernetes directly).
Pros Cons
Much simpler to deploy and operate than OpenStack Smaller community and talent pool than OpenStack or Kubernetes
Centralized, easy to troubleshoot Fewer third-party integrations
Native NVIDIA GPU, NVLink and DPU orchestration Single-instance scale certified at 500 hypervisors; federation needed beyond
VMware migration tools (OneSwap) and DRS equivalent (OneDRS) Several advanced integrations are EE-only
Apache 2.0 CE, open formats, low lock-in Maintenance releases and LTS are subscription benefits
KVM + LXC + managed Kubernetes (OneKS) in one platform LXC lacks live migration and some VM actions
gRPC API for high-concurrency environments (7.2+) Documentation less extensive than OpenStack's

Key Features

Feature Detail
VM management Full lifecycle, live migration, live storage migration, snapshots, backups, resize, EVC for mixed CPU generations
LXC containers Unprivileged system containers with VM-like management
NVIDIA GPU orchestration PCI passthrough, vGPU, NVLink/NVSwitch via Fabric Manager (EE), BlueField DPU, Spectrum-X
OneDRS Cluster load balancing and packing with an ILP solver and usage forecasts
OneKS / OneKE Kubernetes as a Service (OneKS, CE since 7.4) and the RKE2-based OneKE appliance
OneForm Automated cluster provisioning on-premises, on bare metal, and on cloud providers
OneFlow Multi-VM services with elasticity and virtual-router roles
OneSwap vCenter VM and OVA conversion to KVM, batch mode (7.4)
Marketplace Public appliances (OS images, OneKE, Slurm, virtual router)
Multi-tenancy Users, groups, VDCs, ACLs, user/group/cluster-level quotas
Security LDAP/SAML/x509/SSH auth, Sunstone 2FA, security groups, memory encryption, vTPM

Compatibility

Dimension Support (7.4)
Hypervisors KVM, LXC
Storage Ceph (Reef, Squid), NFS, local disks with caching, LVM / LVM thin on SAN, NetApp ONTAP, Pure Storage FlashArray, VirtioFS
Networking Linux bridge, 802.1Q VLAN, VXLAN, Open vSwitch, SR-IOV, DPDK, Spectrum-X, InfiniBand
Cluster providers (OneForm) On-premises hosts, bare-metal and cloud providers such as AWS, i3D.net and Scaleway
GPUs NVIDIA Ampere, Ada, Hopper, Blackwell; Axelera Metis accelerators
Backups Restic (incl. S3), rsync, Veeam B&R 13+ (EE), OneBEX interface
CPU architecture x86_64 and arm64 (aarch64 appliances, including OneKS)

Full matrices: Reference: Certified Platforms.

Alternatives, Migration and Lock-in

  • Alternatives: OpenStack (larger, service-per-function cloud OS), Proxmox VE (hypervisor appliance without cloud self-service), VMware vSphere/VCF, Harvester, Apache CloudStack.
  • Migrating in: OneSwap converts vCenter VMs (including batch and striped transfers in 7.4) and OVA exports. Many virtualization estates arrive from VMware.
  • Lock-in: Low. VM disks are standard qcow2/raw/RBD images, templates are plain text, and the CE is Apache 2.0. The main dependency is on EE-only integrations and support if you rely on them.

Community Health

  • Development led by OpenNebula Systems, with EU and Spanish public funding for the 7.x roadmap (ONEnextgen under IPCEI-CIS, ONEedge5G).
  • Regular six-monthly minor releases with public betas (7.4 beta preceded the July 2026 release).
  • Community forum, public GitHub issue tracker, and a companion appliance project (one-apps) released alongside each version.

Topic Map

  • How-to Guides: install (miniONE, OneDeploy, packages), hosts, VMs, networks, storage, gRPC, OneDRS, security, upgrades, troubleshooting
  • Reference: releases, editions, platforms, ports, drivers, config keys, VM states, ACLs, benchmarks, hardening checklist
  • Explanation: architecture, scheduler and OneDRS, service layer, storage and network models, security model, scale, IPCEI-CIS context

Sources

Source URL
Official website https://opennebula.io
Documentation (7.4) https://docs.opennebula.io/7.4/
Release Notes 7.4 - What's New https://docs.opennebula.io/7.4/software/release_information/release_notes/whats_new/
7.4 "Helix" announcement https://opennebula.io/blog/announcements/opennebula-7-4-helix/
Release Notes 7.2 https://docs.opennebula.io/7.2/software/release_information/release_notes/
7.2 announcement https://opennebula.io/blog/announcements/opennebula-7-2-released/
7.0 Compatibility Guide https://docs.opennebula.io/7.0/software/release_information/release_notes_70/compatibility/
What is OpenNebula EE https://docs.opennebula.io/7.0/software/release_information/release_notes_enterprise/what_is/
Release Policy https://github.com/OpenNebula/one/wiki/Release-Policy/
Release Schedule https://github.com/OpenNebula/one/wiki/Release-Schedule
GitHub repository https://github.com/OpenNebula/one
Docs source repository https://github.com/OpenNebula/website
Introducing OneKS https://opennebula.io/blog/product/introducing-oneks/
IPCEI-CIS initiative https://opennebula.io/initiatives/ipcei-cis/
Subscription plans https://opennebula.io/subscriptions/
Community forum https://forum.opennebula.io
Marketplace https://marketplace.opennebula.io

Questions

Open Questions

  • Which 7.x minor releases carry the LTS designation, and what are their end-of-support dates? (The Release Policy wiki, revision 2026-09-13, defines the model but names no LTS versions.)
  • Is 7.4.1 available to the Community Edition, or EE-only like 7.2.1?
  • Will OneKE (appliance) be deprecated now that OneKS is in CE?
  • Current official subscription prices (Elemental/Standard/Premium) and per-node fees.
  • Independent scheduler and OneDRS performance data at 1,000+ VMs per plan.

Answered Questions

  • How does the gRPC API compare to XML-RPC? The official 7.2 benchmark (1,250 hosts, 20,000 VMs, synthetic mix) shows vmpool.info average latency falling from 0.97 s to 0.43 s at 10 req/s and from 2.15 s to 0.94 s at 30 req/s, 2-3x faster under load. The gain is binary serialization; database, monitoring and driver load still bound overall throughput, and federation is recommended beyond 500 hypervisors per instance. Source: gRPC Integration docs (7.2).
  • How does OneDRS compare to VMware DRS? No published head-to-head benchmark exists. OneDRS (7.0+) uses an integer linear programming solver with forecasted CPU, memory, disk and network usage; supports manual, partial and full automation; packing or balance policies; and (7.4) storage migrations. OpenNebula explicitly positions it as a full-featured alternative to VMware DRS. VMware's resource pools and long production history remain more mature. Source: OneDRS docs, 7.0 release notes.
  • What is the maximum tested scale? A single oned is certified for 500 hypervisors without degradation. Some users run about 2,000, and the key-features page cites over 2,500 nodes in production. The earlier claim of "1,000+ hosts and 30,000+ VMs tested in one cluster" is not in the official docs and was removed. Source: Platform Notes 7.2/7.4.
  • How mature is LXC support? Production-supported with certified host OSes (Ubuntu, Debian, AlmaLinux, Rocky). Not implemented for LXC: live migration, live disk resize, state save/restore, system snapshots, live qcow2 disk snapshots, live capacity resize. 7.2 added NIC hot-plug, recontextualization, NIC PCI passthrough and disk snapshots on LVM, LVM thin, Ceph and raw images. Use KVM when you need live migration. Source: LXC driver docs.
  • Is OpenNebula simpler than OpenStack? Yes. One central daemon and database versus many distributed services; installs take hours with miniONE or OneDeploy.
  • Does OpenNebula support NVIDIA GPUs? Yes. Passthrough and vGPU, NVLink/NVSwitch via Fabric Manager (EE, 7.2), GB200/GB300 validation, BlueField DPUs, Spectrum-X, and NICo bare metal (EE, 7.4). See Release Highlights.
  • Can OpenNebula replace VMware? Yes, that is an explicit goal: OneSwap migration, OneDRS, Veeam integration, LVM SAN storage (CE since 7.4).
  • Which hypervisors are supported? KVM and LXC only in 7.x. Firecracker and LXD were removed in 6.10 and vCenter in 7.0.