This is the third minor release in the Tentacle series.
We recommend that all users update to this release.

Notable Changes
---------------

MDS (Metadata Server)
---------------------

* Fixed a crash and shutdown hang that could occur when ephemeral pins were active and max_mds was set to 0.
* Session reclaim could miss blocklisting an old session; this is now handled correctly.
* Fixed a case where scrub was unable to identify damage from an irreparable hard link.

OSD (Object Storage Daemon)
----------------------------

* BlueStore: Fixed a BlueFS WAL envelope-mode bug that caused write buffer misalignment.
* Erasure Coding: Fixed truncate+write planning for EC shard sizes.
* Fixed a condition that prevented rolling forward of PG log entries.
* Prevented OSDMap::check_health() from asserting when new OSDs are found in a subtree.
* Scrub: "repairing" scrubs are now allowed at all times.

RGW (RADOS Gateway)
--------------------

* Added the ssl_ciphersuites option for the Beast front-end to support TLS 1.3 cipher customization.
* Fixed PutObject's canned_acl comparison bug affecting BlockPublicAcls.
* Fixed crashes occurring on realm reload.
* Implemented CopyObject support for encrypted objects.
* Added mTLS client-certificate authentication support for Kafka notifications.
* Fixed removal of delete markers in lifecycle processing.

RADOS / librados / neorados
----------------------------

* neorados: Fixed an infinite trim loop on empty data log shards.
* Fixed cancellation-slot cleanup in librados/asio's associated executor.

Dashboard
-----------------

* Added a hardware-monitoring dashboard backed by node-proxy metrics.
* Fixed a bind-address regression caused by CherryPy isolation.
* Added support for adding hosts via CSV upload.
* NVMeoF: multiple CLI and UI backports (EC pool support, IO statistics, role management).
* Object: The global RGW Roles tab has been removed. Role management is now scoped under RGW Accounts, where roles can be listed, created, edited, and deleted for a selected account.

ceph-volume
-----------

* Reworked OSD mapper lifecycle handling (LVM + raw) for activate.
* Improved detection of rotational media under dm-crypt to bypass the workqueue correctly.
* Fixed OSD re-deployment issues with disk-selection filters and DB devices.
* Added retry handling for lvs when it returns an empty result or a "devices file is missing" error.

NVMe-oF
-------

* Added configurable delayed failback (default 0, no delay) to accommodate initiators that recover paths with a delay.
* Gateways in the DELETING state now ignore beacons and send empty maps instead of processing them.
* rbd_with_crc32c is now enabled by default via cephadm.
* Introduced a new NVMeoF mgr module. The module automatically creates the ".nvmeof" metadata pool if it does not already exist. Gateway-group state files are stored in this pool unless the user specifies another pool. The module is enabled automatically on fresh installs; on upgrades from an older cluster, it must be enabled manually.

RBD
---

* Fixed a use-after-free bug releasing object map locks during deep copy.
* Fixed memory leaks in PWL discard operations.
* Obsolete primary mirror snapshots are now pruned after relocation.

We recommend users to update to this release.
For detailed release notes with links & changelog please refer to the
official blog entry at https://ceph.io/en/news/blog/2026/v20-2-3-tentacle-released/

Getting Ceph
------------
* Git at git://github.com/ceph/ceph.git
* Tarball at https://download.ceph.com/tarballs/ceph-20.2.3.tar.gz
* Containers at https://quay.io/repository/ceph/ceph
* For packages, see https://docs.ceph.com/en/latest/install/get-packages/
* Release git sha1: 06c2f9c35b67055a8a6fb99d1be236b3c4832ace