OpenStack¶
Summary
OpenStack is the most widely deployed open-source cloud operating system (IaaS): a set of cooperating Python services (Nova, Neutron, Cinder, Glance, Keystone and many more) that turn racks of servers into a multi-tenant, API-driven private or public cloud. It ships every six months, with every .1 release being a SLURP release that supports skip-level upgrades. The current release is 2026.1 Gazpacho (2026-04-01), with 2026.2 Hibiscus planned for 2026-09-30. It is Apache 2.0 licensed and governed by its Technical Committee under the OpenInfra Foundation, which joined the Linux Foundation in 2025.
Overview¶
OpenStack is a modular, service-oriented cloud platform that treats the data center as a programmable resource pool. Each service owns an API, a database schema and worker processes, and the services are glued together by Keystone (identity and service catalog) and RabbitMQ (RPC). It runs telecom NFV clouds, research and HPC clouds, public clouds and enterprise private clouds, and it is one of the main destinations for VMware migrations after Broadcom's licensing changes.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version | 2026.1 "Gazpacho" (2026-04-01), SLURP release |
| Next Release | 2026.2 "Hibiscus", planned 2026-09-30 (release candidates as of 2026-09-25); then 2027.1 "Indri" (SLURP), planned 2027-03-24 |
| Release Cadence | Every 6 months; .1 releases are SLURP (skip-level upgrades between them) |
| Maintained Releases | 2026.1 Gazpacho, 2025.2 Flamingo, 2025.1 Epoxy (Epoxy moves to unmaintained on 2026-10-02) |
| Language | Python (2026.1 requires Python 3.10+, 2026.2 requires 3.11+) |
| License | Apache 2.0 |
| Governance | Technical Committee and project teams; OpenInfra Foundation, part of the Linux Foundation since 2025 |
| Repository | opendev.org/openstack (Gerrit review, Zuul CI; GitHub is a read-only mirror) |
| Project Teams | 42 official teams in governance projects.yaml (2026-09) |
The full release matrix, support phases, component versions and ports are in Reference.
Evaluation¶
-
Why it is better: The most mature and feature-complete open-source IaaS. It covers compute, networking, block/object/file storage, identity, images, bare metal, load balancing, DNS and orchestration behind consistent APIs, with true multi-tenancy (projects, quotas, per-project networks). It is proven at very large scale and has several vendor distributions.
-
When it fits (Applicability):
- Large private clouds (hundreds to thousands of nodes) with many tenants
- Telecom NFV infrastructure
- VMware replacement where self-service and multi-tenancy are needed
- Public or sovereign cloud providers
- Bare metal as a service (Ironic)
- Scientific computing and HPC clouds
-
When it does not fit: a handful of hypervisors without a platform team (see Proxmox VE or OpenNebula), or container-only platforms where Kubernetes on bare metal is enough.
| Pros | Cons |
|---|---|
| Most mature open-source IaaS | Very high operational complexity |
| Apache 2.0, no single-vendor lock-in | Requires a dedicated platform team (or a vendor distro) |
| Large community and vendor ecosystem | Many moving parts (dozens of services plus RabbitMQ, Galera, OVN, Ceph) |
| Proven at large scale (Nova cells, regions) | Steep learning curve |
| VMware migration path (VMware driver, migration tooling) | Upgrade complexity; dependencies do not follow SLURP |
| SLURP releases allow yearly upgrades | Eventlet-to-threads migration still in progress |
| Bare metal via Ironic | Heavy control-plane resource needs |
Architecture¶
The compact view below shows the control plane, shared infrastructure and hosts; the detailed component diagram and the instance-creation sequence are in Explanation.
flowchart LR
subgraph ControlPlane["Control plane"]
KS["Keystone<br/>(identity)"]
NOVA["Nova API, conductor,<br/>scheduler + Placement"]
NEU["Neutron server<br/>(ML2/OVN)"]
CIN["Cinder"]
GLA["Glance"]
HOR["Horizon / Skyline"]
end
subgraph Infra["Shared infrastructure"]
MQ["RabbitMQ"]
DB["MariaDB / Galera"]
MC["Memcached"]
OVNDB["OVN NB/SB DBs"]
end
subgraph Hosts["Compute and storage"]
NC["nova-compute<br/>(libvirt/KVM)"]
OVNC["ovn-controller<br/>(Open vSwitch)"]
CEPH["Ceph RBD"]
end
HOR --> KS
NOVA <--> MQ
MQ <--> NC
NOVA --> DB
NEU --> DB
CIN --> DB
KS --> MC
NEU --> OVNDB
OVNDB --> OVNC
NC --> GLA
NC --> NEU
NC --> CEPH
CIN --> CEPH
Core Services¶
The day-one set is Keystone, Nova (with Placement), Neutron, Glance and Cinder, usually plus Horizon. Common additions are Octavia (load balancers), Heat (orchestration), Barbican (secrets), Designate (DNS), Ironic (bare metal), Manila (file shares), Magnum (Kubernetes clusters) and Swift (object storage, or Ceph RGW in its place). The full service map with API ports is in Reference.
Latest Releases¶
- 2026.1 Gazpacho (SLURP, 2026-04-01): parallel live migration connections and vTPM live migration in Nova, one IOThread per instance by default, asynchronous volume attach (microversion 2.101), native threading by default for nova-api/scheduler/metadata, OVN BGP in Neutron, Ironic NFS/CIFS virtual media and a standalone networking service. Direct upgrade from 2025.1 Epoxy is supported.
- 2025.2 Flamingo (2025-10-01): Neutron runs in native threading mode (eventlet removed), OVN agent replaces the OVN metadata agent, Nova
managerandserviceroles. - 2026.2 Hibiscus (planned 2026-09-30): release-candidate highlights include AMD SEV-SNP and Intel TDX guests in Nova, and BGP EVPN and Private VLAN plugins in Neutron.
Details: Release Highlights.
Notable Changes 2024-2026¶
| Change | When | Impact |
|---|---|---|
| OpenInfra Foundation joins the Linux Foundation | Intent 2025-03-12, completed mid-2025 | Legal and event home changes; technical governance unchanged |
| Neutron Linux bridge driver removed | 2025.1 Epoxy | Migrate to ML2/OVN or ML2/OVS before upgrading |
| Nova Hyper-V driver removed; Winstackers retired | 2023-2024 | Windows hosts no longer supported as hypervisors |
| TripleO retired | 2024-01-09 | Red Hat moved to RHOSO (operators on OpenShift) |
| Murano, Sahara, Senlin, Solum, EC2-API retired | 2024-05-10 | Remove before upgrading; no replacements upstream |
| Monasca retired | 2025-08-11 | Use Telemetry (Ceilometer, Aodh) or Prometheus-based monitoring |
| Kolla-Ansible drops Swift deployment | 2025.1 (Kolla-Ansible 20.0.0) | Use Ceph RGW or deploy Swift separately |
| Eventlet removal | 2025.2 onward | New thread-pool tunables; test memory sizing |
The full retirement list is in Reference.
Deployment Options¶
| Tool | Summary |
|---|---|
| Kolla-Ansible | Official; Ansible deploys Kolla containers; the most common community path |
| OpenStack-Ansible | Official; Ansible roles on hosts or LXC |
| OpenStack-Helm | Official; Helm charts that run the control plane on Kubernetes |
| Genestack | Rackspace's Kubernetes-based distribution built on OpenStack-Helm charts (Apache 2.0) |
| Canonical OpenStack (Sunbeam) | Canonical's Kubernetes-native deployment with snaps and charms |
| Red Hat OpenStack Services on OpenShift | Red Hat's operator-based product |
| DevStack | Development only |
How-to recipes: Kolla-Ansible, OpenStack-Helm, upgrades.
Licensing and Pricing¶
| Offering | Cost |
|---|---|
| Self-hosted upstream | Free (Apache 2.0); you carry operations |
| Canonical OpenStack (Ubuntu Pro / support) | Support subscriptions; Canonical states LTS versions get up to 12 years of support |
| Red Hat OpenStack Services on OpenShift | Enterprise subscription |
| Mirantis OpenStack for Kubernetes | Enterprise subscription |
| Managed private or public cloud (for example Rackspace, VEXXHOST, OVHcloud) | Per-resource or per-node pricing |
| SUSE OpenStack Cloud | Discontinued; no longer sold (Canonical reports EOL of versions 8 and 9 in 2021 and 2022) |
Compatibility and Requirements¶
- Hypervisors: KVM/QEMU via libvirt (primary), VMware vCenter, IBM z/VM, and Ironic for bare metal. Hyper-V and Xen are no longer supported.
- Networking: ML2/OVN (default in DevStack), ML2/OVS, SR-IOV. Linux bridge was removed in 2025.1.
- Storage: Ceph (RBD, RGW, CephFS), LVM, NFS and many vendor arrays via Cinder drivers.
- Host OS (Kolla-Ansible 2026.1): Ubuntu 24.04, Debian 13, Rocky Linux 10, CentOS Stream 10.
- Minimum footprint: DevStack or Kolla-Ansible all-in-one on one node for labs; production normally uses three controllers (for RabbitMQ and Galera quorum) plus compute and storage nodes.
Matrix: Compatibility Matrix.
Alternatives and Migration¶
- Alternatives: OpenNebula (lighter cloud manager), Proxmox VE (virtualization appliance), Kubernetes with KubeVirt or Harvester (VMs on Kubernetes), Apache CloudStack, VMware vSphere (commercial incumbent).
- Lock-in: low at the software level (open APIs, Apache 2.0, many distributions), but the real switching cost is operational knowledge and the chosen deployment tool; moving between Kolla-Ansible, OpenStack-Helm and vendor distros usually means a redeploy and workload migration.
- Community health: active six-month releases with 40+ official teams, but a long-term trend of project retirements (Murano, Sahara, Senlin, Monasca and others) as contributor effort concentrates on the core services.
Topic Map¶
- How-to Guides: deploy, operate, upgrade and troubleshoot OpenStack (2026.1 Gazpacho).
- Reference: release series and support phases, SLURP upgrade matrix, runtimes, component versions, service and port map, drivers, deployment tooling, hardening checklist.
- Explanation: core and supporting services, the instance-creation request flow, SLURP release model, governance, Eventlet removal, OVN networking, Ceph integration, multi-region, security model.
- Comparisons: pointer to the domain comparison pages.
Related Topics¶
- Comparisons — index of comparison notes involving OpenStack
- Proxmox VE vs OpenNebula vs OpenStack
- Infrastructure Platforms Comparison (Docker, Kubernetes, OpenStack, OpenNebula)
- Kubernetes — runs on OpenStack (Magnum, Cluster API) and hosts OpenStack control planes (OpenStack-Helm, Genestack)
- OpenNebula — lighter-weight cloud manager
- Proxmox VE — virtualization appliance for smaller estates
- Docker — container runtime used by Kolla images
Sources¶
Questions¶
Open Questions¶
- Confirm the final 2026.2 Hibiscus release date and component versions after 2026-09-30, and update Key Facts.
- When will nova-conductor and nova-compute default to native threading, and when will eventlet mode be removed from Nova?
- Exact date the OpenInfra Foundation's move into the Linux Foundation closed (announced 2025-03-12; sources say mid-2025).
- No upstream source publishes a "recommended" Ceph version per OpenStack release; what do Kolla/Ceph-Ansible/cephadm test against for 2026.1?
Answered Questions¶
- How should parallel live migrations be tuned in Gazpacho? — Two separate knobs:
[DEFAULT] max_concurrent_live_migrations(default 1) limits how many migrations one host runs, and the new[libvirt] live_migration_parallel_connections(default 1) opens several QEMU connections for a single migration's memory transfer; each connection can use a CPU core, and combining it with post-copy needs QEMU 10.1+. Other levers:live_migration_bandwidth,live_migration_completion_timeout, a dedicated migration network and shared (Ceph) storage. No published benchmarks for 2026.1. — Nova 2026.1 configuration reference - How does Magnum compare to Cluster API for Kubernetes lifecycle? — Magnum's in-tree driver builds clusters with Heat (Fedora CoreOS); the Swarm and Mesos drivers are gone. The Magnum team also maintains
magnum-capi-helm, which drives Cluster API behind the Magnum API. Running Cluster API with the OpenStack provider (CAPO) directly is Kubernetes-native and GitOps-friendly; Magnum remains useful when tenants need a self-service OpenStack API for clusters. — governance projects.yaml, Magnum repository - What is the status of the eventlet removal? — A TC-selected goal. Neutron runs in native threading mode since 2025.2; Nova 2026.1 defaults nova-api, nova-scheduler and nova-metadata to native threads (conductor and compute can opt in) and still labels the mode experimental; other projects are at various stages. See Explanation.
- Which Ceph release to use with 2026.1? — Ceph is versioned independently. As of 2026-09 the active Ceph releases are Tentacle (20.2.x, target EOL 2027-06-01) and Squid (19.2.x, target EOL 2026-10-31); Reef is past EOL. Pick a release your deployment tool tests. — ceph
releases.yml - What is the latest release? — 2026.1 "Gazpacho" (2026-04-01), SLURP; 2026.2 "Hibiscus" is planned for 2026-09-30.
- What upgrade paths are supported? — Adjacent releases (2025.2 to 2026.1) and SLURP to SLURP (2025.1 to 2026.1). See the SLURP matrix.
- Does OpenStack support bare metal? — Yes, via Ironic (PXE/iPXE, Redfish virtual media, including NFS and CIFS media since 2026.1).
- What is the minimum deployment? — One node for labs (DevStack or Kolla-Ansible all-in-one); production usually starts at three controllers plus compute nodes.