problem
CloudStack builds its Ceph RBD connection strings with the legacy Ceph option auth_supported=cephx. This option was removed in Ceph Tentacle 20.2.4. As a result, every RBD operation performed by the KVM agent through librados now fails, and the agent cannot bring up the RBD storage pool:
**agent.err:**
libvirt: Storage Driver error : internal error: failed to set RADOS option: auth_supported
**agent.log:**
2026-08-27 00:00:13,468 ERROR [kvm.storage.LibvirtStorageAdaptor] (AgentRequest-Handler-3:[]) (logid:e0478a61) Failed to create RBD storage pool: org.libvirt.LibvirtException: internal error: failed to set RADOS option: auth_supported
2026-08-27 00:00:13,468 ERROR [kvm.storage.LibvirtStorageAdaptor] (AgentRequest-Handler-3:[]) (logid:e0478a61) Failed to create the RBD storage pool, cleaning up the libvirt secret
In ACS Host state is Disconnected
Code:
plugins/hypervisors/kvm/src/main/java/com/cloud/hypervisor/kvm/storage/KVMPhysicalDisk.java, lines 56-62
versions
ACS: 4.22.1.1
Hypervisor OS: KVM on Rocky Linux 9.8
libvirt: 11.10.0
Ceph client packages: librados2 / librbd1 / ceph-common 2:20.2.4-0.el9
Ceph cluster: 20.2.4 Tentacle
The steps to reproduce the bug
- Deploy a KVM host with Ceph RBD primary storage and cephx enabled.
- Upgrade the Ceph client packages on the KVM host to 20.2.4 (Tentacle): librados2, librbd1, ceph-common.
- Restart libvirtd and cloudstack-agent.
What to do about it?
Remove auth_supported, it is redundant. When id and key are supplied, the client negotiates cephx anyway, and when they are not, it falls back to whatever auth_client_required in ceph.conf specifies.
It is also possible to use auth_client_required instead of auth_supported.
problem
CloudStack builds its Ceph RBD connection strings with the legacy Ceph option
auth_supported=cephx.This option was removed in Ceph Tentacle 20.2.4. As a result, every RBD operation performed by the KVM agent through librados now fails, and the agent cannot bring up the RBD storage pool:In ACS Host state is Disconnected
Code:
plugins/hypervisors/kvm/src/main/java/com/cloud/hypervisor/kvm/storage/KVMPhysicalDisk.java, lines 56-62
versions
ACS: 4.22.1.1
Hypervisor OS: KVM on Rocky Linux 9.8
libvirt: 11.10.0
Ceph client packages: librados2 / librbd1 / ceph-common 2:20.2.4-0.el9
Ceph cluster: 20.2.4 Tentacle
The steps to reproduce the bug
What to do about it?
Remove
auth_supported, it is redundant. Whenidandkeyare supplied, the client negotiates cephx anyway, and when they are not, it falls back to whateverauth_client_requiredinceph.confspecifies.It is also possible to use
auth_client_requiredinstead ofauth_supported.