Portworx Stork Release Notes
26.4.1
September 8, 2026
New Features
- FADA backup and restore on Portworx clusters with FA/FB driver enabled: Stork now enables Portworx Backup to back up and restore FADA (FlashArray Direct Access) volumes on Portworx Enterprise clusters configured with FA/FB driver enabled. Stork resolves backup requests issued by Portworx Backup from any node in the cluster, and provisions the restore destination PVC. This requires Stork 26.4.1, Portworx Enterprise 3.7.0 or later, and Portworx Backup 3.1.1. For prerequisites and behavior, see Backup and Restore FADA Volumes.
Fixes
| Issue Number | Issue Description | Severity |
|---|---|---|
| PWX-57233 | The Stork leader pod deletes the cluster-scoped stork-webhooks-cfg MutatingWebhookConfiguration during shutdown, even though the surviving Stork replicas still need it to serve admission requests.User Impact: During a routine drain of the node running the Stork leader, all pod admission mutations were interrupted for 15–40 seconds until a new leader was elected and recreated the configuration. In KubeVirt environments, this window could cause active live VM migrations to abort. Resolution: Stork no longer deletes stork-webhooks-cfg on pod shutdown. For Operator-managed deployments, the Portworx Operator handles cleanup when Stork is disabled or uninstalled. For operator-less deployments, delete the stork-webhooks-cfg MutatingWebhookConfiguration and the stork-webhook-secret Secret manually after the Stork pods are removed.Affected Versions: 26.4.0 and earlier | Major |
| PB-16693 | When restoring a RoleBinding whose subjects referenced ServiceAccounts from a namespace not included in the restore namespace mapping, those subjects were dropped from the restored RoleBinding. User Impact: Restored RoleBindings were missing cross-namespace ServiceAccount subjects, breaking RBAC configurations that granted permissions to service accounts in other namespaces. Resolution: Stork now preserves all RoleBinding subjects during restore. Subjects whose source namespace is included in the namespace mapping have their namespace replaced with the corresponding destination namespace; all other subjects are applied unchanged. Stork does not validate subjects in either case.Affected Versions: All versions | Minor |
26.4.0
July 29, 2026
New Features
-
CSI VolumeSnapshot support for VolumeSnapshotSchedules: VolumeSnapshotSchedules for PVCs provisioned by the Portworx CSI driver (
pxd.portworx.com) now automatically use CSI VolumeSnapshots (snapshot.storage.k8s.io/v1) instead of the legacy external-storage VolumeSnapshot API. PVCs on the in-tree Portworx driver continue to use the legacy path. For more information, see Associate a schedule policy using a CSI VolumeSnapshotClass. -
Granular failover and failback by object name: The
storkctl perform failoverandstorkctl perform failbackcommands now support name-based inclusion and exclusion of specific Kubernetes resources, providing precise control over which workloads are activated or deactivated during a DR operation. New flags available on both commands:--include-objectsand--exclude-objects. For more information, see Failover an application and Failback an application. -
Skip last-mile migration on failover/failback: A new
--skip-last-mile-migrationflag onstorkctl perform failoverandstorkctl perform failbackskips the last-mile migration before workloads are activated. For more information, see Failover an application and Failback an application. -
Workload identity for ClusterPair authentication: The
storkctl create clusterpaircommand now supports the--use-workload-identityflag, letting Stork authenticate with the backup location using your cloud provider's workload identity instead of static credentials. Supported only in Gardener clusters provisioned in Amazon Web Services (AWS), Azure, and Google Cloud Platform (GCP). For more information, see storkctl create clusterpair and Prerequisites for Asynchronous Disaster Recovery. -
Forced full-backup cadence supported on CSI cloud snapshots: The Portworx CSI driver now reads
csi.openstorage.org/snapshot-incremental-countfromVolumeSnapshotClass.Parametersand propagates it to the full-backup frequency of the cloud backup request, forcing a full backup when the value is "0". This restores the legacy portworx.io/cloudsnap-incremental-count cadence control on the CSI snapshotter path. Supported values:- Integer N >= 1 implies 1 full backup followed by N incremental backups per cycle.
- "0" implies every backup is a full backup.
- Absent implies cluster default value 7 as full backup frequency.
For more information, see Create a VolumeSnapshotClass.
Improvements
| Improvement Number | Improvement Description |
|---|---|
| PWX-50016 | Stork's scheduler extender now serves a /healthz endpoint. Portworx Operator 26.2.0 and later configures readiness and liveness probes on the Stork deployment using this endpoint, so application pods using schedulerName: stork-scheduler no longer fall back to the default scheduler while Stork is restarting. |
| PWX-44985 | Creating a MigrationSchedule or Migration object using storkctl on a security-enabled cluster with guest access disabled no longer requires you to manually provide auth annotations. storkctl now automatically adds the openstorage.io/auth-secret-name and openstorage.io/auth-secret-namespace annotations, defaulting to px-admin-token and the target namespace, so migrations no longer fail with a Access denied without authentication token error. |
26.3.1
June 16, 2026
Improvements
| Improvement Number | Improvement Description |
|---|---|
| PWX-54863 | Stork's scheduler extender now applies hyperconvergence-aware scoring (hyperconvergence or anti-hyperconvergence) for pods whose PVCs are sourced from VolumeSnapshots, PVC clones, or local snapshots when the StorageClass uses volumeBindingMode: WaitForFirstConsumer. This improves I/O locality and reduces east-west network traffic for workloads such as backup restore jobs that create PVCs from VolumeSnapshots. |
26.3.0
June 1, 2026
New Features
Stork log telemetry
Portworx Enterprise telemetry now supports collecting and uploading Stork logs to Pure1. These logs assist in troubleshooting and observability of Stork operations. For more information, see Enable Stork telemetry.
Improvements
| Improvement Number | Improvement Description |
|---|---|
| PB-14672 | The BackupSync controller now uses origin markers for the ApplicationBackup and ApplicationRestore resources it creates, preventing unauthorized resource creation from bypassing Portworx Backup access controls. |