A major release focused on infrastructure integrity, security and operational flexibility: server firmware drift detection, automatic switch drift detection, switch lifecycle tracking, OIDC authentication, expanded Pure Storage support, ad-hoc BGP sessions, container and NVIDIA NVLink support in preview, and more.
MetalSoft version 7.5 is now out. This is a major release that extends infrastructure management across servers, networking, storage and virtualization, while adding stronger controls around authentication and infrastructure integrity. It also introduces new capabilities for AI infrastructure and gives operators more visibility into deployment and platform behavior. Here are the highlights.
Infrastructure Integrity and Lifecycle Management
Server firmware drift detection
Server firmware is now tracked against a defined baseline, and a warning is sent when drift is detected. Drift detection can be enabled per server, with defaults set at the site level, and the platform can be configured to prevent the allocation of servers with firmware drift or health issues. Detected incidents can be acknowledged once reviewed. This extends the drift detection introduced for switches in 7.4 to the servers themselves.
Automatic switch drift detection
Network device drift detection is now enabled automatically on all switches, so operators no longer need to activate it device by device. Monitoring can still be tuned per network device, including the check interval, or switched off where it is not wanted.
Switch lifecycle events
Fabric Manager now tracks the lifecycle stage of each switch explicitly, with new statuses, transition events and lifecycle actions. ZTP-managed switches can be returned to the planned state, and decommissioned devices remain visible in the device list, giving operators a clearer view of where each network device is in its life.
Security and Access Control
OIDC authentication
MetalSoft now supports OpenID Connect (OIDC) as an authentication method alongside SAML and LDAP, with the same group mapping. This expands the platform's integration options for organizations with centralized identity management.
API key and session controls
API keys can now be given an expiration period, set globally or per user and account, and administrators can restrict which users are allowed to hold an API key at all. Administrators can also control whether a user may stay logged in from more than one browser at a time.
Two-factor authentication recovery codes
2FA recovery codes are now shown in the UI during setup and can be used to log in when the authenticator is unavailable. Administrators also have recovery options for users locked out of 2FA.
Network and Fabric Management
Ad-hoc BGP sessions with external systems
Fabric Manager can now create ad-hoc BGP sessions with external peers such as VCF clusters, making it easier to connect a MetalSoft-managed fabric to systems that MetalSoft does not itself manage.
Layered fabric deployment
The different layers of a fabric can now be deployed in separate operations rather than in a single step, giving administrators finer control over how a fabric is rolled out.
Manual LAG/MLAG IDs
For the cases that need it, the LAG/MLAG ID can now be set manually instead of being allocated automatically.
Storage
Pure Storage Everpure support
MetalSoft 7.5 adds support for Pure Storage Everpure storage arrays, expanding the range of storage infrastructure that can be managed through the platform.
Secure multi-tenancy for Pure Storage
The Pure Storage integration now supports realms, with hosts and access policies scoped to a realm and a QoS policy per realm covering IOPS, bandwidth and capacity. This gives service providers and shared-platform teams stronger tenant isolation and more granular control over storage resources.
Custom QoS and snapshot policies
Custom snapshot policies are now supported for Pure FlashArray and FlashBlade, and custom QoS and snapshot policies for NetApp and Huawei OceanStor Dorado arrays.
Virtualization and AI Infrastructure
Container support (preview)
The Incus integration can now provision containers as well as virtual machines. Available as a preview in 7.5, this brings container workloads under the same orchestration layer as bare metal and VMs. VMs and containers also gain support for custom variables, and users can now edit VM properties and perform power operations directly.
NVIDIA NVLink support (preview)
MetalSoft 7.5 introduces preview support for NVIDIA NVLink: the system automatically configures NVLink zones for GPU virtual machines. Together with the NUMA-aware VM placement introduced in 7.4, this extends MetalSoft's ability to orchestrate dense GPU infrastructure for AI workloads.
Extensions
Site-specific configuration and output variables
Building on the per-site extension variables introduced in 7.4, extensions now support site-specific configuration and output variables, making it easier to adapt a single extension to individual environments instead of maintaining separate implementations.
Extension lifecycle improvements
Extensions now support versioning and are validated when activated. Workflow extensions can be updated in place, the Ansible content of an extension can be edited by an administrator, and an extension definition can include a RAID or server profile.
OpenShift cluster expand and shrink
The OpenShift extension now supports expanding and shrinking clusters, in addition to installing and managing them.
Observability and Integration
Deployment events in Kafka
New Kafka events cover deployment operations, including job progression and failures, so external systems can follow deployment activity and tie MetalSoft operations into existing automation and observability pipelines.
Application metrics
Extensive metrics on the MetalSoft application's own performance are now exposed to Grafana and Prometheus, giving operators visibility into the health of the platform itself, not just the infrastructure it manages.
Also in this release: ELI, MetalSoft's AI investigator, is now invoked whenever a health check changes state; quota limits are broken down per account and user in the admin UI; subnet capacity is shown in the UI, including for OOB subnets; SAML and LDAP configurations can be validated before use; and MetalSoft can be set up without a mail server. As usual, the release also includes a large number of bug fixes and UI improvements. The complete list is in the release notes.
Want to see MetalSoft 7.5 in action on your own infrastructure? Book a demo with our team.
