Release 2026_020 (2026-06-01)

Impact

25.11

Machines will reboot to activate a changed kernel.

NixOS 25.11 platform

  • roles/kvm: support Ceph Pacific and qemu-10.1 (PL-131408)

    not yet enabled by default, will be manually rolled out location-wise

  • Document upgrade procedures for k3s. (PL-132803)

  • fc-ceph: Work around a known Ceph bug that leaves OSDs stuck after maintenance. (PL-135425)

  • add the loki-relay role that enables cross-rg log shipping (PL-135168)

  • Pull upstream NixOS changes, security fixes, and package updates:

    • chromedriver: 148.0.7778.167 -> 148.0.7778.178

    • chromium: 148.0.7778.167 -> 148.0.7778.178

    • discourse: 2026.1.3 -> 2026.1.4

    • firefox: 150.0.3 -> 151.0.1

    • gitaly: 18.11.2 -> 18.11.3

    • github-runner: 2.333.1 -> 2.334.0

    • gitlab: 18.11.2 -> 18.11.3

    • gitlab-ee: 18.11.2 -> 18.11.3

    • gitlab-pages: 18.11.2 -> 18.11.3

    • gitlab-workhorse: 18.11.2 -> 18.11.3

    • grafana: 12.3.6 -> 12.3.6+security-01

    • imagemagick6: 6.9.13-38 -> 6.9.13-48

    • linuxKernelStable: 6.12.87 -> 6.12.90

    • linuxKernelVerify: 6.12.87 -> 6.12.90

    • mastodon: 4.5.9 -> 4.5.10

    • mongodb: 7.0.31 -> 7.0.34

    • nodejs_20: (new version missing)

    • nss_latest: 3.123.1 -> 3.124

    • pdns: 4.9.14 -> 4.9.15

    • phpPackages.composer: 2.9.7 -> 2.9.8

    • postgresql: 17.9 -> 17.10

    • postgresql_14: 14.22 -> 14.23

    • postgresql_15: 15.17 -> 15.18

    • postgresql_16: 16.13 -> 16.14

    • postgresql_17: 17.9 -> 17.10

    • postgresql_18: 18.3 -> 18.4

    • varnish80: 8.0.1 -> 8.0.2

Detailed Changes