Release Notes
8.5.2
Release Date: 2026-02-09
New Features
- Added support for Veeam Data Cloud (VDC) Vault AWS location profiles.
Improvements
- Updated Virtual Machines dashboard page to include Last Backup time.
- Virtual machine snapshots capture additional metadata related to snapshot consistency. See VM Snapshot Consistency Metadata for more details.
Bug Fixes
- Fixed an issue where performing a large number of parallel VM export actions could result in an inability to obtain a repository lock, causing export action failure.
- Fixed an issue in environments using OpenShift authentication where the Job used to automatically extract required certificates was missing expected label, annotation, and resource settings.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Fixed StorageSecurityContextBinding validation failing when the namespace is omitted in storageSecurityContextRef. The controller now correctly defaults to the binding's namespace, matching standard Kubernetes reference behavior.
- Clusters with Kasten DR configured to export to a VDC Vault location profile using the "Create local catalog snapshots only" option may experience failures when attempting to restore the KDR backup to a different cluster. It is recommended that such environments update Kasten DR configuration to "Export local catalog snapshots".
8.5.1
Release Date: 2026-01-22
New Features
- Added support for integrating Veeam Kasten with Red Hat Advanced Cluster Management (ACM) Observability Service, including automated cluster name and ID detection from OpenShift infrastructure, Prometheus remote write configuration, and external labels for ACM integration.
- Added support for performing
backupPrehookandbackupPosthookBlueprint actions on custom resources.
Improvements
- Phone Home data is now sent to https://analytics.kasten.io instead of https://storage.googleapis.com.
Bug Fixes
- Fixed an issue where backups of namespaces with many virtual machines could become stuck indefinitely after a CSI error.
Security Issues
- Upgrade to Go 1.25.6 to address CVEs: CVE-2025-61726, CVE-2025-61728, CVE-2025-61731, CVE-2025-68119, CVE-2025-68121.
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Fixed an issue where the PVC owner discovery mechanism would fail for Blueprints assigned to a Namespace or cluster-scoped resource.
Deprecations
- The
VeeamVaultlocation and secret types for location profiles using Azure-based VDC Vault have been deprecated. Existing profiles should be updated to use the currentVeeamVaultAzuretype. See Profiles for usage details.
8.5.0
Release Date: 2026-01-08
Release Summary
The launch of Veeam Kasten for Kubernetes v8.5 introduces several new capabilities and improvements to support the growing trend of modern virtualization and diverse needs of container-based environments, including:
-
VM-Centric Protection Policies: Policies can now select Virtual Machines as first-class resources, enabling users to define backup and recovery strategies based on VMs rather than just at the namespace or label level. By automatically identifying resource dependencies for each VM, this innovation simplifies management and improves protection for virtualized workloads running within Kubernetes environments. See Protecting VMs on Kubernetes for details.
-
VM-Centric Recovery Improvements: Multiple enhancements have been made to the recovery experience for VMs:
-
VM-centric policies protect each VM as independent restore points, enabling users to confidently restore individual VMs without manual identification and filtering of dependencies.
-
Multiple VMs from one or more namespaces can now be easily restored as part of a single, batch operation.
-
Individual disks within a VM can now be restored, providing greater flexibility and efficiency when recovering data volumes or rolling back an OS volume while retaining existing data volumes.
-
Users can now choose to retain the original MAC addresses of network interfaces during restore, required in some environments to provide consistent network identity and connectivity post-restore.
-
-
Kubernetes-native File Recovery: File Recovery Sessions enable users to securely browse and recover individual files from exported restore points without restoring an entire application or volumes. This critical recovery capability supports both Filesystem mode PVCs for container-based workloads and Block mode PVCs for virtualized workloads. See Restoring Individual Files for details.
-
Restore Point Validation: Enables users to verify the integrity of exported restore points before using them for recovery, especially useful when the backup target does not support immutability. Validation supports both full scans of selected Filesystem mode PVCs and faster metadata-only scans. See Validate RestorePoint for details.
-
Expanded Azure Integrations: Kubernetes clusters running on Microsoft Azure can now take advantage of multiple new integrations to enhance security and flexibility:
-
Azure Key Vault Integration: Users can now leverage Key Vault to provide the KDR passphrase used for cluster recovery and securely manage keys used to encrypt restore point data, enhancing data protection and compliance.
-
Azure Federated Identity for Location Profiles: Integration with Federated Identity delivers seamless and secure access to Azure resources, including Azure Blob Storage, without managing long-lived credentials.
-
Azure Files CSI Validation: Users can now use Kasten and volume snapshots to protect shared volumes provisioned via the Azure Files CSI v1.33.4 or later.
-
-
SMB-based Location Profiles: Users can now create Location Profiles backed by SMB shares mounted to the cluster. In addition to broad support object storage, NFS, and Veeam Backup & Replication, Kasten continues to deliver on freedom of choice across the Kubernetes ecosystem.
-
Simplified Encryption Key Rotation: Users can now manage local or externally-managed Passkeys used for encrypting exported data directly from the Dashboard UI.
-
Prometheus Remote Write: The built-in Prometheus instance used by Kasten to store key operational metrics can now be configured to write metrics to any external, Prometheus-compatible monitoring system, enabling unified observability across the enterprise.
New Features
-
Added support for
recovering individual files
from exported restore points using SFTP. In addition to the new
FileRecoverySession API,
k10toolsprovides a simple CLI interface and SFTP client to manage file recovery sessions. - Added support for OpenShift 4.20.
- Added Virtual Machine support to the Restore Points page, allowing users to manage and restore VM-based restore points.
-
Added support for VM-based backup policies
that enable fine-grained protection of individual Virtual Machines using the
k10.kasten.io/virtualMachineRefselector with automatic discovery of VM dependencies. - Added batch restore for Virtual Machines, allowing users to select multiple VMs from the Virtual Machines page to initiate a restore operation.
Improvements
- Updated Restore Point Details view in Kasten dashboard to include all applicable actions.
- Added the
kastenDisasterRecovery.validationTimeoutHelm parameter to configure timeout period for validation of KDR restore points when initiating a KDR restore operation through the dashboard or creating a KastenDRReview via YAML. - Improved restore performance using optimized batch reads for backups exported to object storage locations.
- To improve VM snapshot consistency, Kasten will now attempt to freeze the guest filesystem by default during backup operations. See Guest Filesystem Freezing for more details.
Bug Fixes
- Fixed an issue where KastenDRReview status was not updated after reaching the timeout for KDR restore point validation. The timeout to validate KDR restore points was extended from 5 minutes to 30 minutes to further reduce premature failures in environments where validation may take longer due to number of KDR restore points or environmental factors.
- Fixed an issue that can result in individual policies not performing scheduled runs following a system interruption or upgrade.
- Fixed a workload snapshot failure for StatefulSets that specify a custom ordinal start value.
Deprecations
- Support for OpenShift 4.16 has been removed.
8.0.15
Release Date: 2025-12-18
New Features
- Added support for Azure Key Vault as a passkey provider for encryption key management, enabling envelope encryption of the primary key.
- Added support for Azure Key Vault Secrets as a passphrase provider for Disaster Recovery, allowing KDR passphrase storage and retrieval from Azure Key Vault.
- Added support for Prometheus remote_write to forward Kasten metrics to external monitoring systems such as Grafana Cloud, Datadog, or other Prometheus-compatible endpoints.
- Added search to the Kasten dashboard to allow for quick navigation to specific policies, profiles, and application namespaces based on name.
Improvements
- Improved job throughput under load after reaching concurrency limits defined by
limiter.*PerClusterHelm values. - Improved loading time for Virtual Machines in the dashboard.
Bug Fixes
- Fixed an issue where the Veeam Kasten Disaster Recovery policy fails with "invalid repository password" errors after performing a KDR restore.
- Fixed an issue where excessive keep alive requests resulted in block mode exports failing with an ENHANCE_YOUR_CALM error code.
- Fixed an issue where jobs could become stuck indefinitely after reaching concurrency limits defined by
limiter.*PerClusterHelm values. - Fix incorrect state when clearing filter on Restore Points page
- Fixed an issue where a KDR restore would attempt to import redundant restore points following a successful restore of a catalog snapshot.
Security Issues
- Upgrade to Go 1.25.5 to address CVE-2025-61727 and CVE-2025-61729.
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Deprecations
-
The
k10restoreHelm chart andk10restoreOpenShift operands have been removed. See Veeam Kasten Disaster Recovery for details on alternate options to recover Veeam Kasten.
Other Notes
- Backups exported from Veeam Kasten to a Veeam Backup & Replication (VBR) repository now include Kubernetes application metadata captured by the policy. At this time, no change to existing policies is required and there is no impact to restore operations. Policies exporting to VBR continue to require an additional Kasten location profile for storing each application's Kubernetes metadata.
8.0.14
Release Date: 2025-11-26
Improvements
- Added a new Helm value,
vault.mountPath, to specify an authentication mount path when using Hashicorp Vault with the Kubernetes auth method. This works for both creating a Passkey using the transit engine or when enabling K10 DR using the KV secrets engine. - When removing location profile, you get a warning if there is any existing restore point or policy which uses this profile
Security Issues
- Improved logging security for specific block mode datamover upload Pod invocations. It is recommended to upgrade Veeam Kasten to get this fix.
8.0.13
Release Date: 2025-11-18
New Features
- Added support for OpenShift 4.19.
- Added a new Passkey Management page in the Settings section of the Kasten Dashboard, providing a centralized interface for managing passkeys used to encrypt backup data. The Passkey Management interface supports creating and managing multiple types of passkeys:
- Passphrase-based passkeys
- AWS Key Management Service
- HashiCorp Vault integration
- Using a filter in a backup policy to include resources based on VirtualMachine name now discovers and protects hot plugged volumes.
- Added support for snapshot and filesystem mode export of persistent volumes provisioned by the vSphere CSI driver without requiring a vSphere Infrastructure Profile. See Storage Integration for details.
Improvements
- Introduced support for ED25519 certificates.
- Integrated Go Cryptographic Modules to enhance and maintain compliance with FIPS 140-3 standards.
- Updated to Go 1.25.4.
Bug Fixes
- Support for “no-auth mode” has been fully restored. The “no-auth mode” (used to run K10 without authentication for testing or development) was unintentionally disabled in version 8.0.12.
- Fixed an issue where Gatekeeper constraint violation messages for Kasten policies were not being displayed in the dashboard.
- Fixed an issue where Kasten policies could not be resubmitted following an admission controller validation error in the dashboard.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Deprecations
- Support for OpenShift 4.15 has been removed.
8.0.12
Release Date: 2025-10-29
Known Issues
- Upgrading to Kasten 8.0.8 or later is not recommended for clusters running Kubernetes 1.27, OpenShift 4.14 or earlier versions due to lack of support for SelfSubjectReview API, which may result in dashboard authentication issues. It is recommended to first upgrade to a supported Kubernetes version to ensure compatibility.
Other Notes
- When performing snapshots of KubeVirt VMs, guest filesystem freeze and unfreeze operations are directly invoked by Kasten and no longer depend on a Kanister Blueprint.
- Added new limiter
vmSnapshotsPerClusterto control the number of concurrent VM snapshots per K8s cluster. The default value is 1.
8.0.11
Release Date: 2025-10-21
New Features
- Added an
openshift.consolePlugin.enabledconfiguration value to allow disabling console plugin and related resources on OpenShift.
Bug Fixes
- The previous release of Veeam Kasten enabled FIPS TLS enforcement regardless of whether the underlying system was in FIPS mode or the Veeam Kasten
fips.enabledsetting was set to true. This release fixes that issue by enforcing FIPS TLS only if the Veeam Kastenfips.enabledhelm value is set to true or if the underlying system is in FIPS mode. - Fixed an issue when creating a Location Profile for Dell ECS that led to an unsupported S3 API being used.
- Added
app.kubernetes.io/componentlabel togatewayService. - Fixed an issue where export actions and policy runs could terminate in error when a backup action is deleted. An exception is now raised and the rest of the export process continues.
- Made OpenShift
console-pluginandconsole-plugin-proxydeployments respect global resource configuration.
Security Issues
- Upgrade to Go 1.25.3 to mitigate security vulnerabilities.
- Upgrade to golang.org/x/net@v0.46.0 to address CVE-2025-58190 and CVE-2025-47911.
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Upgrading to Kasten 8.0.8 or later is not recommended for clusters running Kubernetes 1.27, OpenShift 4.14 or earlier versions due to lack of support for SelfSubjectReview API, which may result in dashboard authentication issues. It is recommended to first upgrade to a supported Kubernetes version to ensure compatibility.
Deprecations
- Following Red Hat Marketplace closure in April 2025, Kasten licenses can no longer be purchased via the Red Hat Marketplace. As a result, the Enterprise Term/PAYGO listings have been removed from the Red Hat OperatorHub. Customers currently using either the kasten-k10-operator-paygo-rhmp-bundle or kasten-k10-operator-term-rhmp-bundle operators must refer to KB4774 for transition details.
8.0.10
Release Date: 2025-10-02
Bug Fixes
global.resourceLabelsare now applied to the console-plugin and console-plugin-proxy services when deployed on OpenShift.- Fixed an issue that could delay backup actions for large applications when CSI snapshots fail.
- Consistently applied
app.kubernetes.io/versionandapp.kubernetes.io/componentlabels to all Deployments. - Fixed an issue where Kasten DR could not restore properly when being authenticated with federated credentials.
- Fixed documentation related to Azure Federated Identity installations.
- Fixed an issue where editing a KDR policy that was configured to export snapshots would result in policy validation error.
- Applied
global.resourceLabelsconfiguration to metadata of deployments.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Upgrading to Kasten 8.0.8 or later is not recommended for clusters running Kubernetes 1.27, OpenShift 4.14 or earlier versions due to lack of support for SelfSubjectReview API, which may result in dashboard authentication issues. It is recommended to first upgrade to a supported Kubernetes version to ensure compatibility.
8.0.9
Release Date: 2025-09-20
Known Issues
- Upgrading to Kasten 8.0.8 or later is not recommended for clusters running Kubernetes 1.27, OpenShift 4.14 or earlier versions due to lack of support for SelfSubjectReview API, which may result in dashboard authentication issues. It is recommended to first upgrade to a supported Kubernetes version to ensure compatibility.
Deprecations
- Support for Instant Recovery of PVC data to guest Kubernetes clusters using the vSphere Cloud Native Storage CSI has been deprecated and will be removed in a future release. Standard restore of local or exported Kasten restore points will remain unaffected.
-
The
k10restoreHelm chart andk10restoreOpenShift operands were deprecated in 8.0 release and will be removed in 8.5. See Veeam Kasten Disaster Recovery for details on alternate options to recover Veeam Kasten.
Other Notes
- Added instructions for cleaning up Custom Resource Definitions after uninstalling Kasten via Helm.
8.0.8
Release Date: 2025-09-05
New Features
-
Added Helm flags
global.resourceLabelsandglobal.ephemeralResourceLabels. Useglobal.resourceLabelsto specify labels on all Kasten PVCs, Network Policies, Services, and Pods, andglobal.ephemeralResourceLabelsto specify labels only on ephemeral Kasten PVCs, Network Policies, Services, and Pods. - Veeam Kasten Disaster Recovery restore timeout can be configured using
kastenDisasterRecovery.restoreTimeoutMinutesHelm value to avoid timeout. - Added support for Kubernetes 1.33.
-
Made
prometheus.server.resourcesandprometheus.configmapReload.prometheus.resourcesrespect theglobal.resourcessettings if defined. Prometheus-specific overrides still take precedence over global values.
Bug Fixes
- Resolved an issue with error propagation in the Veeam Kasten Disaster Recovery restore workflow to ensure errors are properly returned when timeout occurs.
- Fixed kubectl server side dry run support for Kasten resources.
-
Fixed merging of Helm
global.resourcesvalues for individual container requests and limits. This prevents the possibility of referencing non-existent configuration keys and subsequentCreateContainerConfigErrorerrors.
Security Issues
- Upgrade to Go 1.24.7 to mitigate security vulnerabilities.
Known Issues
- Upgrading to Kasten 8.0.8 or later is not recommended for clusters running Kubernetes 1.27, OpenShift 4.14 or earlier versions due to lack of support for SelfSubjectReview API, which may result in dashboard authentication issues. It is recommended to first upgrade to a supported Kubernetes version to ensure compatibility.
Upgrade Notes
- Removed the Helm flags
kanisterPodCustomLabelsandkanisterPodCustomAnnotations.
Deprecations
-
Deprecated the Helm flag
global.podLabelsin favor ofglobal.resourceLabelsandglobal.ephemeralResourceLabels.global.podLabelswill be removed in a future release. - Removed support for Kubernetes 1.29. OpenShift 4.16 clusters continue to be supported.
Other Notes
- Modified Resource Requirement documentation for
global.resourcesusage andephemeral-storagefields.
8.0.7
Release Date: 2025-08-22
New Features
-
Added optional
workerPodMetricSidecar.resources.[requests|limits].ephemeral-storagehelm configuration values to control the ephemeral storage resource quota for dynamically created metrics sidecar containers. -
Added
genericVolumeSnapshot.resources.[requests|limits].ephemeral-storagehelm configuration values to control the ephemeral storage resource quota for dynamically created worker pods. -
Added optional helm configuration values for
gateway.resources.[requests|limits].ephemeral-storage. These propagate to the Gateway deployment resource quota. -
Added optional
global.resources.[limits|requests]helm configuration value. If specified, this value gets applied to all Kasten K10 pods deployed by the chart (except Prometheus - seeprometheus.resources). Can be overridden byresources.<service-name>values for individual pods. This value also serves as a fallback for dynamically created pods that do not have specific resource configurations defined. - Updated the Licenses page with latest license and node usage cards and a new compliance status card that identifies nodes running Veeam Kasten-protected workloads that are not licensed.
Bug Fixes
- Updated Veeam Kasten license provisioning for Azure Marketplace
- Fixed an issue causing Kanister blueprint operations involving
MultiContainerRunto not be FIPS compliant since Veeam Kasten version 7.0.12 - Fixed an issue where Kasten DR was not restoring properly when using an Azure location profile authenticated with federated credentials.
- Fixed an issue where Azure Location Profiles could not enable immutable backups when being authenticated with federated credentials.
- Fixed documentation related to Azure Federated Identity installations.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Deprecations
- Kanister blueprint functions CreateVolumeSnapshot, WaitForSnapshotCompletion, CreateVolumeFromSnapshot and DeleteVolumeSnapshot are no longer available.
8.0.6
Release Date: 2025-08-08
New Features
- Added support for Azure Federated Identity for authenticating location profiles for OpenShift on Azure.
Bug Fixes
- Added missing Helm and Kubernetes well-known labels to the console-plugin and console-plugin-proxy pods.
- Fixed a performance issue leading to timeouts when loading Policies dashboard page.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.24.6 to mitigate security vulnerabilities.
8.0.5
Release Date: 2025-07-25
New Features
- Added a ValidateAction to the K10 API, allowing users to validate volume data exported as part of a backup.
- Added support for the
k10.kasten.io/minimumExportDiskSizeannotation in StorageClass to influence temporary PVC sizing during exports. Supported units for the annotation value include: Ki, Mi, Gi, Ti, Pi, Ei, k, M, G, T, P, E. - Added a feature to preserve MAC addresses for virtual machines during restoration, to enhance network stability and configuration consistency across VM lifecycle.
- Added RestorePoint Validation with support for Full Data Scan, Metadata Only mode, and Fast Fail to ensure backup integrity.
- Extended trial license evaluation period from 30 days to 60 days.
- Added explicit grace period availability indicators in UI.
Bug Fixes
- Fixed export failures for PVCs smaller than 4Gi when using exporterStorageClassName with AWS io1.
- Fixed an issue with Kasten Disaster Recovery backup failing when
multicluster.enabledis set to false via Helm. - Fixed a performance issue leading to timeouts when loading Profiles
- Fixed an issue in license validation and status handling.
Security Issues
- Increased the security of the generated backup repository passwords.
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Other Notes
- Updated Enterprise license grace period from 50 to 30 days.
- Removed the grace period for trial licenses.
8.0.4
Release Date: 2025-07-10
New Features
-
Added the
datastore.cacheSizeLimitMBHelm parameter to control the size limit of emptyDir volumes used by temporary Pods performing data mover operations. The parameter accepts the following values:null(Default) - Limit is dynamically determined by Kasten0- Disables emptyDir size limit3000or greater - Explicitly sets the emptyDir size limit in MiB
- Added UI support for Import policies to restore to an alternate namespace.
- Added UI support for Import policies to optionally enable overwriting existing resources during restore.
Bug Fixes
- Fixed an issue that broke FIPS compliance in versions 8.0.2 and 8.0.3.
- Fixed an issue where labels set via the
global.podLabelsparameter were not being applied to all Pods. - Fixed an issue where annotations set via the
global.podAnnotationsparameter were not being applied to all Pods. - Fixed an issue requiring using a literal hostname rather than an IP address when accessing the Kasten UI if configuring a VDC Vault location profile.
- Fixed an issue where Veeam Vault secret type was not supported in GSB/GVS environments
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.24.5 to mitigate security vulnerabilities.
Other Notes
VirtualMachineInstanceMigrationresources are now automatically excluded from snapshots. Restore points created before this that includeVirtualMachineInstanceMigrationresources are unaffected and will require manual exclusion of these resources when restoring virtual machines.
8.0.3
Release Date: 2025-07-01
New Features
- Added support for restoring individual volumes of existing virtual machines in OpenShift Virtualization 4.18 and later.
- Added support for Veeam Data Cloud (VDC) Vault location profiles.
Bug Fixes
- Prevents restore failures caused by attempting to recreate Pods with a pre-set nodeName, which is typically assigned by the scheduler.
- Fixed an issue where KDR policies with export enabled would fail during export to NFS location profiles.
- Fixed an issue where the volume counter in the restore form displayed higher counts than actual volumes.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Version 8.0.3 should not be used if requiring FIPS compliance.
- When configuring a VDC Vault location profile, you currently must use a literal hostname to access the Kasten UI rather than an IP address. For example, you would need to use
http://localhost:8080/k10/#/rather thanhttp://127.0.0.1:8080/k10/#/when accessing the Kasten UI to go through the VDC Vault location profile configuration process. - Multi-cluster Manager registration is not supported for Veeam Data Cloud (VDC) Vault location profiles.
8.0.2
Release Date: 2025-06-13
New Features
- Added
cacertconfigmap.keyHelm parameter to set an optional, custom key for the CA certificate bundle ConfigMap. - Added support for allowing CSI ephemeral volumes in the Kasten SecurityContextConstraints (SCC) profile.
- Added support for SMB location profiles.
Bug Fixes
- Fixed an issue that made versions 7.5.10, 8.0.0 and 8.0.1 not FIPS compliant.
- Fixed an issue that made the
kanister-toolsimage always run in FIPS mode which could lead to TLS errors. - Fixed an issue where KDR reviews could fail in environments using the vSphere CSI if the local catalog snapshot was no longer available.
- Fixed an issue with Kasten Disaster Recovery that would cause validation to fail when using Vault or AWS Secrets Manager.
- Fixed an issue that prevented setting up Kasten Disaster Recovery via the UI when Legacy KDR is enabled.
- Fixed a logout redirection issue when launching the Veeam Kasten dashboard from the Veeam Backup & Replication Console.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.24.4 to mitigate security vulnerabilities.
Known Issues
- Versions 7.5.10, 8.0.0, 8.0.1, and 8.0.2 should not be used if requiring FIPS compliance.
Deprecations
- Legacy KDR mode has been deprecated and will be removed in a future release. All clusters should be updated to a supported Quick KDR configuration.
- Support for Kubernetes 1.26 and OpenShift 4.13 has been removed.
- Support for Kubernetes 1.27 and OpenShift 4.14 has been removed.
8.0.1
Release Date: 2025-05-30
Bug Fixes
- Fixed a performance issue leading to timeouts when loading Policies.
- Fixed an issue where prometheus was incorrectly reporting the gateway service was unhealthy.
- Improved loading performance of the Restore Points page for admin users. Non-admin users with access to many namespaces may still experience slow loading of the Restore Points page.
- Fixed an authentication redirection issue when launching the Veeam Kasten dashboard from the Veeam Backup & Replication Console.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.24.3 to mitigate CVE-2025-22873.
8.0.0
Release Date: 2025-05-15
Release Summary
Veeam Kasten for Kubernetes v8.0 continues Veeam's leadership in Kubernetes data protection by introducing new and enhanced capabilities related to operations management, security, and modern virtualization workloads, including:
-
Expanded Veeam Backup & Replication Compatibility: Support for exporting to VBR repositories has been expanded to all clusters where storage provisioners support block mode export, and includes support for exporting KubeVirt volumes.
-
Virtual Machines Dashboard: New dashboard page to provide visibility into KubeVirt-based workloads and dependent resources across the cluster.
-
Restore Point Dashboard: New dashboard page to simplify management of available restore points and initiate restore operations.
-
Policies Dashboard: Redesigned dashboard page to improve policy management at scale with new table-based view, expanded search and filtering options, and new policy details view.
-
Self-Service Cluster Migrations: New Veeam Kasten validating admissions policies allow non-admin users to securely perform import and restore operations of existing backups on alternate clusters.
-
Reduced Privileges for Veeam Kasten Services: Minimized attack surface by adopting individual ServiceAccounts for each Veeam Kasten microservice and reducing permissions where possible.
-
ISO 27001 Certification: Veeam Kasten is now certified, ensuring industry-leading security and compliance for Kubernetes data protection.
-
Encryption Key Rotation: Veeam Kasten now supports the creation and simultaneous use of multiple passkeys to allow easy key rotation for exported data.
-
Expanded KDR Compatibility: Veeam Kasten Disaster Recovery (KDR) improves compatibility and resilience for environments with limited snapshot capabilities.
-
Multi-Architecture Support: Veeam Kasten now supports deployment to Kubernetes clusters using either 64-bit ARM or POWER CPU architectures, in addition to existing x86_64 CPU support.
New Features
- Added helm flag to enable installation of Validating Admission Policy which enforces permissions during Kasten policy creation for non-admin users.
- Added support for Import actions for application-scoped policies created by non-admin users.
- The Multi-Cluster Distributions UI has been updated to a table view and a multi-step form for creating distribution resources.
- Added support for the use of multiple, active passkeys.
- Added support for OpenShift 4.18.
- The Policies page has been updated for additional clarity and visual consistency. A list of all policies in a namespace can now be viewed, filtered, and sorted in a table.
- A Policy view page has been introduced to provide a detailed view of the policy and its status.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Known Issues
- Fixed issue with multicluster global policies where after distributing, the
imageRepoProfile.namespacefield inbackupParametersis incorrect. -
Environments where Veeam Kasten is installed using the
kubernetes.io/portworx-volumein-tree Portworx storage provisioner do not currently support the new default Veeam Kasten Disaster Recovery (KDR) mode. Prior to upgrade, it is recommended that any applicable Veeam Kasten installation should explicitly disable Quick DR mode using Helm values.
Upgrade Notes
-
Kasten now uses deployment specific service accounts instead of the
k10-k10service account for a default helm install. Kasten continues to support using a customer provided service account name via the helm valueserviceAccount.name.NOTE: Customers who previously configured their Vault server for Kubernetes Auth with the
k10-k10service account must re-configure the Vault server with thecrypto-svcservice account before an upgrade. -
Following upgrade to 8.0.0, any Veeam Kasten installations that do not explicitly set
kastenDisasterRecovery.quickMode.enabled=falseand have Veeam Kasten Disaster Recovery (KDR) enabled will now default to Quick DR with local catalog snapshot. This mode is recommended for all installations where Veeam Kasten has been deployed to storage that supports both the ability to create and to restore from local snapshots. See documentation for details on alternate configurations. -
Upgrading to this version changes the manner in which passkeys are handled. Performing a KDR backup is recommended prior to upgrading.
Deprecations
-
The
k10restoreHelm chart is deprecated and will be removed in a future release. See Veeam Kasten Disaster Recovery for details on alternate options to recover Veeam Kasten.
7.5.10
Release Date: 2025-04-18
New Features
- Added support for restoring VMs with overriding image references on SUSE Virtualization (Harvester).
- Added support for unencrypted VM image backup, restore, and migration on SUSE Virtualization (Harvester).
Bug Fixes
- Links to the Kasten documentation in the UI have been updated to reflect the new documentation structure.
- Fixed the missing link to Grafana on the Data Usage page when Grafana is installed.
Other Notes
- Starting with Veeam Kasten v8.0, all new and existing installations will default to Quick DR mode for Veeam Kasten Disaster Recovery (KDR). This mode is recommended for all installations where supported, snapshot-capable storage is available. Prior to upgrading to this version, any Veeam Kasten installation deployed using storage that lacks the ability to create or restore from local snapshots should explicitly disable Quick DR mode using Helm values.
7.5.9
Release Date: 2025-04-03
Bug Fixes
- Fixed an issue where users without RBAC permission to list actions may encounter timeouts during loading of dashboard activity section.
- Fixed an issue causing panic and executor pod restarts after some FCD snapshot errors.
- Fixed an issue where while using Veeam Kasten Disaster Recovery on OpenShift environment, an incorrect error was being displayed in case of file permissions issue.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.23.8 to mitigate CVE-2025-22871.
Deprecations
- Legacy pages for Location and Infrastructure Profiles, which were previously still available using features flags, have been removed from the UI.
Other Notes
-
The SBOM download URL has been updated to
https://docs.kasten.io/downloads/<version>/sboms/sboms-<version>.tar.gz. The SBOM for the latest version can also be downloaded fromhttps://docs.kasten.io/downloads/latest/sboms/sboms-<version>.tar.gz. - Starting with Veeam Kasten v8.0, all new and existing installations will default to Quick DR mode for Veeam Kasten Disaster Recovery (KDR). This mode is recommended for all installations where supported, snapshot-capable storage is available. Prior to upgrading to this version, any Veeam Kasten installation deployed using storage that lacks the ability to create or restore from local snapshots should explicitly disable Quick DR mode using Helm values.
7.5.8
Release Date: 2025-03-20
New Features
- Added support for Kubernetes 1.32.
- Improved the
VirtualMachinesnapshot and restore workflow to automatically include cluster scoped resources that are referred in VirtualMachine.
Bug Fixes
- Fixed an issue where ephemeral pods created during KDR restore were missing
required-sccannotation which was causing failures while writing files in ephemeral pods in OpenShift environments. - Fixed an issue where during KDR restore, Kasten deployments were not getting scaled down due to existing deprecated fields in OpenShift environments.
- Fixed an issue that could cause the Block-mode upload Pod to become stale under certain conditions.
Security Issues
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
Deprecations
- Removed support for Kubernetes 1.28.
Other Notes
- The default value of the cache limit for snapshot and export workflow is set to 500MB. This change is to avoid the cache from growing indefinitely and consuming more storage.
7.5.7
Release Date: 2025-03-11
Release Summary
Veeam Kasten v7.5.7 is a re-release of v7.5.5 that corrects packaging and documentation issues.
Known Issues
- Fixed issue of missing k10tools images for Veeam Kasten v7.5.5.
- Fixed issue of missing release notes for Veeam Kasten v7.5.6.
7.5.5
Release Date: 2025-03-08
Bug Fixes
- Resolved the image copy failure that occurred during the offline installation of the Kasten 7.5.4 Operator.
- A more helpful validation error message is now displayed when K10DR validate fails on the Configure DR page.
Security Issues
- Upgrade to Go 1.23.7 to mitigate security vulnerabilities.
Other Notes
- The Activity Section Filter in the UI now returns individual root actions instead of grouped actions when filtering by Action and grouped Policy Runs when filtering by Policy name.
7.5.4
Release Date: 2025-02-25
Bug Fixes
- Corrected Operator metadata which caused the Kasten Operator to not be listed in the Red Hat Marketplace for the amd64 platform with the 7.5.3 release.
- Fixed an issue where Pods created while restoring a Veeam Kasten Disaster Recovery backup were using the default service account. This includes Pods with prefix restore-data-dr-, data-mover-svc- and restorectl-validate-. These Pods will now run with the service account used by other Kasten Pods.
- Fixed a bug in the validation of immutable settings for policies that use the VBR scale-out backup repository.
Security Issues
- Update K10 services base image to pull in latest security updates.
- Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Upgrade to Go 1.23.6 to mitigate security vulnerabilities.
7.5.3
Release Date: 2025-02-06
New Features
- Application details panel in Veeam Kasten dashboard has been improved to show the policies selecting that namespace.
- Added support for exporting NetApp ONTAP-NAS-Economy volume snapshots created using Trident CSI v24.10.0 or later.
Bug Fixes
- Fixed a potential panic in
aggregatedapis-svcwhen running Kasten DR restore. - Fixed an issue where RetireActions associated with blueprints were failing due to missing
custom-ca-bundle-storeConfigMap. - Fixed an issue where
imagePullSecretswere not being set in affinity pod created during Veeam Kasten Disaster Recovery workflow - Fixed the formatting of documented
KastenDRRestoreexamples. - Fixed the ability to set the
limiter.executorReplicasvalue.