NEWS
Incus 7.0 LTS Locks the Community Fork In for Five Years
Incus 7.0 LTS is the LXD fork’s second long-term line through June 2031, with a kernel 6.12 floor, no MinIO, and monthly 7.4 already ahead.
Incus 7.0 LTS shipped on May 5, 2026 as the Linux Containers project’s second long-term line, with support booked through June 2031. It is the five-year branch for system containers, OCI application containers, and virtual machines, and it succeeds Incus 6.0 LTS, which is now on security-only maintenance through June 2029.
The feature list is long. The bill is longer: a kernel 6.12 floor, CGroup v1 gone, MinIO ripped out of storage buckets, and a monthly 7.x train that had already reached 7.4 by late August.
Incus 7.0 LTS Holds Support Until June 2031
Project leader Stéphane Graber posted the release on May 5, calling it a clean jump for people on Incus 6.23 and for people still on Incus 6.0.6 LTS. The LTS window matches LXC 7.0 LTS and LXCFS 7.0 LTS. The team promises support until June 2031, with bug fixes, security fixes, and small usability work in 7.0.x point releases for the first two years, then security-only care for the last three.
Two hundred and four people contributed between the 6.0 LTS and 7.0 LTS lines, 45 of them between 6.23 and 7.0. The 7.0 tarball also closed 9 security issues from a 7ASecurity review run in March: 7 rated moderate and 2 rated low. The write-up of that independent security audit by 7ASecurity went public on September 8, 2026.
INCUS 7.0 LTS IN FOUR FIGURES
- Support end: June 2031, after two years of 7.0.x point releases and three years of security-only care.
- Contributors: 204 people from 6.0 LTS to 7.0 LTS, 45 of them after 6.23.
- Security: 9 issues closed in 7.0, 7 moderate and 2 low, from the 7ASecurity review.
- Kernel floor: Linux 6.12, chosen because it is an upstream long-term kernel.
Graber’s own walkthrough went up the same day on the Zabbly channel. The monthly branch kept moving after that, so the LTS line is the freeze, not the tip.
#Incus 7.0 LTS is now out!
That's already the second Long Term Support release for the Incus project and it should be a great upgrade both for users of Incus 6.23 and those on 6.0.6 LTS!https://t.co/zaIrOyJtMl— Stéphane Graber (@stgraber@hachyderm.io) (@stgraber) May 5, 2026
The 2023 LXD Split Now Has a Second LTS
Incus exists because Canonical moved LXD to Canonical on July 4, 2023, after more than eight years under Linux Containers. The community fork kept the Apache 2.0 license and the original maintainers, including Graber, Christian Brauner, and Serge Hallyn. Incus 6.0.0, tagged April 4, 2024, was the first long-term line and the version jump that lined the project up with LXC.
That first LTS made Incus usable as production software. The second one, two years later, is the point where staying on the fork is a five-year ops decision rather than a protest checkout. People who remain on 6.0 LTS still get security fixes through June 2029. They do not get the 6.x features that needed database or on-disk changes too large to backport.
FROM THE LXD SPLIT TO THE SECOND LTS
- July 4, 2023: Canonical takes LXD in-house; Linux Containers later hosts Incus as the community fork.
- April 4, 2024: Incus 6.0.0 LTS is tagged, the first five-year line, supported through June 2029.
- May 5, 2026: Incus 7.0 LTS is announced with LXC 7.0 LTS and LXCFS 7.0 LTS.
- July 10, 2026: Incus 7.0.1 LTS ships as the first LTS point release, with bug fixes, security fixes, and backported enhancements.
- August 28, 2026: Incus 7.4 lands on the monthly branch, well ahead of the frozen 7.0 line.
- September 8, 2026: 7ASecurity’s Incus audit report is published, covering the review that fed the May fixes.
Packaging lagged the announcement by hours, not months. Graber said Ubuntu 26.04 builds were already hitting daily images on May 5, with the lts-7.0 package repo due right after, while an operator on the Linux Containers forum still saw the older lts-6.0 pointer on the Zabbly repo that afternoon.
Kernel 6.12 Is the New Floor
As a major release, 7.0 raises the baselines. The daemon wants Linux 6.12, Go 1.25, QEMU 8.2, LXC 6.0.0, nftables 1.0.0, and dnsmasq 2.90. Optional stacks move too: Open vSwitch 2.15.0 and OVN 23.03.0 when those plugins are in use, ZFS 2.1.0 and LVM 2.03.11 for those storage drivers.
MINIMUM VERSIONS IN INCUS 7.0 LTS
| Component | Minimum | When it applies |
|---|---|---|
| Linux kernel | 6.12 | Required |
| Go | 1.25 | Required to build |
| QEMU | 8.2 | Required for VMs |
| LXC | 6.0.0 | Required |
| nftables | 1.0.0 | Required |
| dnsmasq | 2.90 | Required |
| Open vSwitch | 2.15.0 | When OVS or OVN is used |
| OVN | 23.03.0 | When OVN is used |
| ZFS | 2.1.0 | When ZFS is used |
| LVM | 2.03.11 | When LVM is used |
Graber told the forum the 6.12 cut is a documented LTS kernel, not a claim that every older host will crash. He listed full PIDFD support, VFS idmap support, and newer netlink APIs as the kinds of pieces 7.0 expects.
There’s a decent chance that your kernel will be fine, we picked 6.12 as the new baseline because it’s an upstream LTS.
Stéphane Graber, project leader, Linux Containers forum
That still leaves a real gap on conservative Ubuntu hosts. Ubuntu 24.04 LTS shipped kernel 6.8.0 by default in May 2026. Getting to a 6.12-class kernel there meant installing linux-image-generic-hwe-24.04, which was on 6.17.0 at the time. Ubuntu 22.04 is further behind. The people who want a five-year daemon pin are often the same people who pin an older distro kernel, and 7.0 makes that pairing harder.
CGroup v1 Support Is Gone
The announcement listed CGroup v1 and xtables (iptables, ip6tables, ebtables) among the legacy pieces being dropped. Graber was blunter on the forum: CGroup v1 is fully removed in Incus, and in LXC and LXCFS too. A host without it may still boot the daemon, but the related controls will not work. The GitHub side of 7.0 matches that, with pull requests that remove CGroup v1 and xtables rather than leave them as warnings.
It’s fully removed and not just at the Incus level but also in LXC and LXCFS. It may still be possible to run Incus on a system without it, but all related features will be unavailable/broken.
Stéphane Graber, project leader, Linux Containers forum
The CLI is stricter as well. Parsing lost a pile of old special cases so subcommands behave the same way. Anyone with scripts that leaned on those quirks will find out on first run, not in a changelog footnote.
Why the MinIO Backend Had to Go
Storage buckets in Incus used to mean MinIO. By February 2026 that was a five-year liability: MinIO no longer maintained upstream, distros were starting to drop the package, and unfixed CVEs were showing up on the open-source side. Graber milestoned a replacement for 7.0 so the LTS line would not carry a dead project until 2031.
Rather than wire in another object store, Incus now speaks the S3 bits it actually needs inside its own listener. Clients still see S3. Existing buckets convert to the new on-disk layout (plain files plus separate metadata) the first time they are opened. The old MinIO metadata is kept in case it is useful later. The trade is an extra wait on that first access, not a new API.
Cluster shutdown got a matching production knob. core.shutdown_action still defaults to a clean local shutdown. Set it to evacuate and a clustered node tries to move as many instances as it can to other members before it goes down. Backup tooling for VMs gained a low-level NBD endpoint and dirty-bitmap controls so ordinary backup software can do incremental copies without a custom Incus agent.
What 6.0 LTS Users Finally Get
Graber’s team backported aggressively into 6.0.x, so the jump from 6.0.6 LTS is shorter than a two-year changelog suggests. The leftovers are the features that needed schema or disk format changes. They are the reason 7.0 is a different product from a 6.0 box that has been patched on time.
FEATURES 6.0 LTS NEVER RECEIVED
- OCI application containers: First shipped in Incus 6.3, now on the LTS line, running in the same confined environment as system containers.
- Dependent storage volumes: From 6.23, custom volumes can be tied to an instance so snapshots, migration, backups, and deletes follow the instance.
- Network address sets: From 6.12, reusable IPv4 and IPv6 groups that ACLs can name instead of repeating address lists.
- LINSTOR: Remote storage with DRBD-style replication, now a first-class LTS driver.
- TrueNAS: From 6.16, a remote TrueNAS pool via the TrueNAS API and iSCSI.
- CPU baselines: From 6.4, a CPU baseline in cluster groups so mixed hardware can expose a common flag set for live migration.
OCI support is the one that changes who Incus competes with. You add an OCI remote and launch from a registry the same way you launch a system image, including resource limits and syscall interception. Graber’s own demo pulled MySQL and WordPress from Docker Hub:
incus remote add docker https://docker.io --protocol=oci
incus launch docker:mysql mysql -c environment.MYSQL_DATABASE=wordpress (plus user, password, and a random root password) came up as CONTAINER (APP) with a normal instance IP. WordPress launched the same way against that IP. The type column is the tell: these are application containers under Incus, not a second runtime bolted on the side.
Dependent volumes close a different hole. A volume marked dependent=true cannot be snapshotted on its own; an instance snapshot creates the matching volume snapshot, and deleting the instance deletes the volume. Address sets let an ACL reject traffic to a named group such as $cloudflare-dns without copying four addresses into every rule. CPU baselines let a group compute shared flags, or pin an explicit model such as EPYCv2 with svm turned off, so live migration across mixed hosts has a defined CPU rather than a hopeful default.
One operator on the forum called the 6.0 LTS to 7.0 LTS upgrade seamless. The friction sits before that, on the kernel, cgroup, and firewall floor, not in the database migrate.
Monthly Releases Have Already Reached 7.4
The LTS freeze did not pause the monthly branch. Incus 7.1 arrived on May 30, 2026, 7.2 on June 26, and 7.4 on August 28. Those builds carry work that will not show up on 7.0 unless it is a bug, a security fix, or a small usability backport. Incus 7.0.1 LTS, tagged July 10, 2026, is that backport vehicle. Graber said it carried a lot of bug fixes, security fixes, and backported enhancements. Debian’s incus 7.0.1-1 hit the archive the same day.
MONTHLY RELEASES AFTER 7.0 LTS
| Release | Date | On the LTS line? | Headline extras |
|---|---|---|---|
| 7.0 LTS | May 5, 2026 | Yes | Five-year freeze, S3 listener, raised floor |
| 7.1 | May 30, 2026 | No | Volume rebuild, more S3 work, CPU topology for VMs |
| 7.2 | June 26, 2026 | No | Per-instance SELinux, plus a large security batch |
| 7.0.1 LTS | July 10, 2026 | Yes | Point release: fixes and selected backports |
| 7.4 | August 28, 2026 | No | Secure Boot key tools, near-live container moves |
7.2 is the reminder that “LTS” is not a substitute for 7.0.1. That monthly cut closed eight security issues, several of them critical host-file problems in crafted images, and Graber told people to update. LTS users get that class of fix through 7.0.x, not by sitting on the May tarball. Tooling already assumes the point release: Incus Compose 1.2.0, shipped August 14, 2026, wants 7.0.1 or 7.2 before it will attach compose networks with static addresses, gateways, and NAT.
7.4’s extras show the other side of the split. Near-live container moves on ZFS or btrfs copy the filesystem in snapshots while the guest keeps running, then take a short stop for the last increment. Secure Boot key management and a one-time --override-boot flag are VM-admin work the LTS branch does not pretend to track. Anyone who needs those features is on monthly. Anyone who needs June 2031 is on 7.0.1 and the next 7.0.x after it.
The fork that left Canonical in 2023 now has a second five-year product, a raised host floor, and a monthly line that will keep pulling ahead. The production choice is which of those clocks you are willing to run.
Frequently Asked Questions
How long is Incus 7.0 LTS supported?
The 7.0 branch is supported through June 2031, and the security-only half of that window is timed to the next LTS, Incus 8.0, after which 7.0 gets security fixes only. That two-plus-three split is the same cadence Linux Containers has used for LXC and LXCFS for about ten years, so 6.0 LTS remains on security-only care through June 2029 in parallel.
Can you run Incus 7.0 on Ubuntu 24.04?
Ubuntu 24.04’s default kernel in May 2026 was 6.8.0, below the 6.12 floor, so a stock 24.04 host is a poor match unless you install linux-image-generic-hwe-24.04, which was on 6.17.0 then. Graber had Ubuntu 26.04 building for the Zabbly daily repo on May 5, 2026, with the lts-7.0 suite due the same day, which is the cleaner LTS-to-LTS pairing.
Does Incus 7.0 still use MinIO for S3 buckets?
No. Buckets convert from MinIO’s on-disk format to Incus’s own layout the first time they are accessed, a pass that can take a few minutes on a large bucket, and the original MinIO metadata is retained. After that conversion the client API is still S3, with no extra flags.
What is the difference between Incus 7.0 LTS and Incus 7.4?
7.0 LTS is the frozen five-year line; 7.4 is a monthly feature cut from August 28, 2026, and those features land on 7.0 only if they qualify as a bug fix, a security fix, or a small usability backport in a 7.0.x point release. The current LTS bugfix tarball is incus-7.0.1, tagged July 10, 2026, and that is the build LTS hosts should run.
How do you try Incus 7.0 without installing it?
Linux Containers runs a browser demo at linuxcontainers.org/incus/try-it that boots the current Incus on their hardware. Instance images come from images.linuxcontainers.org, and OCI launches still need skopeo on a real host because Incus uses it to talk to registries.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
