8.0.70 Release Notes

Release Date: 22 June 2026

Corrected Issues in Aviatrix Release 8.0.70

Issue Description

AVX-75872

Fixed a locking race condition during Controller upgrade where the initial setup process and post-upgrade actions could acquire conflicting locks, causing post-upgrade configuration steps to fail or require manual intervention.

AVX-76719

Fixed an issue where Controller restore operations could stall for approximately 30 minutes during the scheduler shutdown phase due to connectivity issues with AWS API endpoints or invalid/expired IAM credentials.

AVX-77487

Fixed an issue on Site-to-Cloud (S2C) gateways where customized NAT rules configured on S2C interfaces were not honored by the gateway’s NAT translator, leading to incorrect or missing address translation on traffic traversing those tunnels.

Known Issues in Aviatrix Release 8.0.70

Issue Description

AVX-62003

Azure gateway image upgrades may fail when the Controller does not have the required Azure image subscription access. During the upgrade, the system deletes the existing gateway before validating subscription availability, which can result in gateway deletion without a replacement being created. This leaves dangling gateways in the Controller and can cause potential service outages.

Impact:

  • Existing gateways may be deleted during image upgrade

  • Replacement gateway creation fails due to missing subscription

  • Customers may experience connectivity loss and dangling gateway entries in the Controller

  • Manual intervention required, leading to support escalations

Workaround:

None. To avoid outages, ensure the Controller subscription includes access to the required Azure image before attempting upgrades.

AVX-62299

When upgrading from Controller version 7.1 to 7.2 or 8.0, Spoke Gateways with routing through a Public Subnet Filtering (PSF) Gateway may fail to upgrade and become unreachable if the PSF Gateway has not been upgraded first. This issue affects AWS environments where Spoke Gateway route tables are configured to point to a PSF Gateway.

To avoid this issue, follow the correct upgrade sequence:1. Upgrade the PSF Gateway first.

  1. Wait for the PSF Gateway upgrade to complete successfully.

  2. Then upgrade the dependent Spoke Gateways.

AVX-62506

During a gateway software upgrade, traffic matching DCF WebGroup rules may be briefly dropped during the upgrade. This impacts both Layer 7 (HTTP/HTTPS) and Layer 4 traffic and occurs across all supported cloud providers (AWS, Azure, and GCP). The disruption typically lasts a few seconds but may vary depending on gateway load and policy complexity.

Workaround:

None

Recommendations:

  • Schedule gateway upgrades during maintenance windows or low-traffic periods.

  • Use HA deployments and upgrade gateways one at a time in HA pairs.

  • Monitor logs for "Failed to load policy" messages to confirm when policies are reloaded.

AVX-64868

In some scenarios involving rapid VRRP state transitions, the keepalived VRRP state may not be reported accurately to the Controller. This can result in temporary discrepancies between the actual VRRP status and what is displayed in the Controller UI, leading to confusion and difficulties during troubleshooting.

Impact:

  • Controller UI may show incorrect VRRP status such as both peers reporting Primary or Initializing

  • No impact on actual VRRP traffic handling or failover behavior.

Workaround:

  • Use diagnostic logs to verify actual VRRP state

AVX-66631

Transit gateways with large-scale tunnel deployments (1300+ tunnels) may experience extended traffic loss during image upgrades. Although the image upgrade completes successfully, traffic may remain down for several minutes afterward due to delayed tunnel reconfiguration.

Workaround:

  • Schedule maintenance windows to account for potential traffic loss beyond upgrade completion.

  • Consider staggering upgrades across transit gateways to reduce impact.

  • Monitor tunnel and route service status post-upgrade through CoPilot UI.

Impact:

  • Traffic loss may persist after image upgrade completes

  • Route service startup is blocked until all tunnels are sequentially reconfigured

  • Configuration push may time out with Context cancelled during Phase 1 Create error

AVX-67126

Dry-run validation may fail when upgrading the Controller from version 8.0.10 to 8.1.0 due to a gateway version mismatch error. This occurs when the upgrade path starts from 8.0.0, progresses to 8.0.10 successfully, but encounters a dry-run failure when proceeding to 8.1.0.

AVX-67571

In Oracle Cloud Infrastructure (OCI) environments, OpenVPN clients cannot connect to VPN gateways configured with DUO multi-factor authentication (MFA). Connection attempts fail with ECONNREFUSED errors during tunnel establishment, preventing authentication from completing.

Impact:

  • VPN tunnels cannot be established to DUO-enabled OCI gateways

  • Only affects OCI deployments with DUO MFA

  • Other authentication methods (OKTA, LDAP) work normally

Workaround: No current workaround. Users may temporarily switch to OKTA or LDAP authentication if feasible.

AVX-68013

In Controller version 8.0.10, Spoke-to-Transit attachments initiated through Terraform may fail with a decode check_task_status failed error during gateway creation.

This issue occurs when multiple API calls are executed in rapid succession, causing the Controller to occasionally return an empty response body for the check_task_status API.

Affected Scenario:

  • Spoke-to-Transit attachments created using the Aviatrix Terraform provider.

  • More likely during parallel or batch gateway deployments across any cloud (AWS, Azure, GCP, OCI).

Impact:

  • Terraform reports an error such as unexpected end of JSON input.

  • The Spoke-to-Transit attachment may still succeed, but Terraform marks the operation as failed.

Workaround:

  • Retry the Terraform operation.

  • Reduce parallelism for Terraform runs if possible.

AVX-68561

In large-scale deployments with 1300+ gateways, enabling Distributed Cloud Firewall Site-to-Cloud (DCF S2C) can cause gateway configurations to become out of sync with the Controller. Even after disabling DCF S2C, the issue may persist and lead to elevated Controller resource usage.

Impact:

Gateway configurations may show as out of sync in the Controller UI

Controller CPU utilization (conduit process) increases significantly

Performance degradation may occur during DCF S2C operations

Issue may persist after disabling DCF S2C

Workaround:

Monitor Controller CPU usage before enabling DCF S2C in large-scale environments.

Consider enabling DCF S2C during scheduled maintenance windows.

For deployments with 1300+ gateways, evaluate the necessity of DCF S2C functionality.

AVX-68726

On Azure Controllers with Controller Security Group Management enabled, existing gateway might go to keepalive fail status while creating a new gateway.

Due to this bug, while creating a new gateway the Controller may automatically disable Controller Security Group Management, which impacts the connectivity between gateway and controller.

Impact:

  • Controller Security Group Management may be disabled unexpectedly.

  • Security group rules of the SG attached to controller might get deleted

Workaround: Enable "Controller Security Group Management" manually, or contact Aviatrix Support for assistance.

AVX-68887

When attaching VPN users to profiles using the attach_vpn_user_to_profile API, the CoPilot or Controller UI may continue to display the user profile as N/A even though the attachment operation completes successfully.

In some cases, users later reappear as active but still show no profile association in the UI. This results in a display inconsistency between the UI and the backend state.

Impact: VPN user profile assignments may appear unsuccessful in the UI, which can cause confusion during profile management. There is no functional impact: the VPN profile is correctly assigned in the backend, and users can connect to the VPN as expected.

Affected Scenario: OpenVPN profile management operations that use API-based user-to-profile attachment.

Workaround: None.

AVX-69649

The migration dry-run EIP accounting does not include public IPs that are not part of the Elastic IP quota, potentially producing inaccurate dry-run results.

Impact:

  • Dry-run migration reports may show incorrect EIP usage

  • Actual migration may encounter unexpected EIP limitations

Workaround:

Manually verify EIP allocation and quotas before performing the migration. Contact Aviatrix Support for assistance.

AVX-71122

In some environments, after the Identity Provider (IdP) rotates its SAML signing certificate, the Aviatrix Controller may fail to fetch and update the new certificate from the configured metadata URL.

As a result, the Controller continues to use a stale certificate, which causes signature verification errors during SAML authentication.

Impact: SAML single sign-on (SSO) authentication fails. Users may experience repeated login failures or timeouts and are unable to access the Controller dashboard using SAML.

Workaround: Contact Aviatrix Support to manually update the SAML certificate on the Controller.

AVX-71135

When upgrading to Controller 8.1, the database migration may fail if VPC tunnel records contain string values in the timestamp field instead of numeric values.

During migration, the process attempts to convert these non-numeric timestamp strings to floating-point values, which results in a conversion error and causes the upgrade to fail.

Impact: The upgrade to Controller 8.1 cannot complete and the system remains on the previous version.

Workaround: Contact Aviatrix Support for assistance.

AVX-71672

When upgrading the Controller to version 8.1, the database migration may fail if the tunnel rtt_avg field contains None values. The migration logic expects either a numeric value or the string "N/A", and encountering a None value causes the upgrade to stop.

Impact:

  • Upgrade to 8.1 cannot complete

  • Controller remains on the previous version

Workaround: Contact Aviatrix Support for assistance in correcting the database values before retrying the upgrade.

AVX-71820

When deploying a load balancer–enabled VPN gateway with an overlapping VPN CIDR on Controller versions 8.0, 8.1, or 8.2, the gateway creation fails.

Impact:

  • VPN gateway deployment fails

  • Error message does not clearly indicate the root cause

Affected Scenario: Load balancer–enabled VPN gateway deployments on Controller versions 8.0, 8.1, and 8.2.

Workaround:

Ensure that the VPN CIDR does not overlap with existing gateways behind the load balancer before deployment. Contact Aviatrix Support for assistance.

AVX-72207

When upgrading OpenVPN gateways to Controller version 8.1 (including 8.1.11 and 8.1.20), where profiles that contain FQDN-based policies may result in service disruption due to a DNS resolution limitation.

Affected Scenario:

  • OpenVPN enabled gateways with profiles that include policies using FQDNs.

Impact:

  • Users once connected to VPN, cannot access the whitelisted FQDNs in the OpenVPN Profiles.

Workaround:

  • There is currently no workaround. Users should roll back the affected gateways to a previous 8.0.x release to restore normal functionality.

AVX-72369

When multiple syslog profiles are configured on the Controller, performing a gateway image upgrade results in gateways being removed from syslog profiles that have only a subset of gateways specified in the include list.

Impact:

  • Remote syslog logs are no longer forwarded to the configured syslog servers for the affected gateways

Workaround:

Manually re-add the required gateways to the affected syslog profiles after the upgrade.

AVX-72835

When upgrading to Controller 8.1, the database migration may fail if a High Availability Gateway (HAGW) entry appeared before its corresponding primary gateway in the database collection. During migration, the process relies on a strict ordering — primary gateway data must be initialized before the HAGW is processed to correctly populate gateway group data. The migration may fail or leave behind gateway entries in the wrong order in the database, which can lead to further issues.

Impact:

  • The upgrade to Controller 8.1 may fail to complete

  • Gateway entries may be stored in an incorrect order in the database

Workaround:

Contact Aviatrix Support for assistance.

AVX-72871

Controller software upgrade to version 8.1 may fail with the error "Please reload the page in order to upgrade" due to an issue with the database migration when the database contains string values instead of integers for the cloud_type field.

Impact:

  • The upgrade to version 8.1 will not be completed.

  • The Controller will remain on the previous version.

Workaround:

Contact Aviatrix Support for assistance in correcting the database values before retrying the upgrade.

AVX-73001

In environments where Spoke Gateways are configured with customized SNAT policies pointing to Transit Gateway VTI interfaces, upgrading Controller to version 8.1.20 may result in loss of the default route. This issue is not limited to Transit FireNet with Egress through Firewall setups, it can also occur when a default route is learned over BGP by the Transit Gateway and propagated to Spoke Gateways, as long as customized SNAT is in use.

This issue may remove the default route in the spoke gateway pointing to the Transit Gateway tunnels, resulting in traffic egressing through unintended interfaces.

Affected Scenario: Spoke gateways configured with customized SNAT policies pointing to Transit Gateway VTI interfaces, upgrading Controller to version 8.1.20

This includes but is not limited to Transit FireNet with Egress through Firewall setups and environments using BGP-learned default routes propagated from Transit to Spoke Gateways.

Impact:

Traffic may bypass the Transit Gateway, leading to traffic disruption or loss.

Workaround:

No workaround is currently available. Contact Aviatrix Support for assistance.

AVX-73061

The Cloud Asset Inventory (CAI) service has a memory leak in its L1 cache. When cloud instances such as VMs are removed from the cloud provider, the associated network interfaces remain cached and are never cleaned up.

Impact:

  • In environments that regularly cycle VMs (such as those using spot instances), the CAI service memory consumption grows over time and is never reclaimed.

  • This can lead to high memory usage by the CAI service, potentially affecting Controller performance.

Workaround:

Contact Aviatrix Support for assistance with periodic CAI service restarts to reclaim memory.

AVX-73629

During a Controller software upgrade from version 8.0 to 8.1, the database migration may overwrite the VPC name field with incorrect data when an old VPC record contains a pre-existing 'name' key set to the gateway name. Affected VPC records become unfindable via index lookups, which can disrupt Controller operations that reference those VPCs.

Impact:

  • Controller upgrades from 8.0 to 8.1 may corrupt the VPC name field for records containing a stale 'name' key.

  • Affected VPC records cannot be retrieved through standard index lookups.

  • Controller operations referencing those VPCs may behave unexpectedly.

Workaround:

Contact Aviatrix Support for assistance.

AVX-73836

In environments where Duo Authentication is enabled for Client VPN, Duo-authenticated users may intermittently fail to connect to the VPN Gateway.

The gateway may log the following error message:

Duo OpenVPN: Received 403 Client duo_openvpn version 2.4 is deprecated and no longer supportedThis occurs because the gateway uses an older Duo OpenVPN client library version that is no longer supported by the Duo service.

Impact:

Users configured with Duo authentication may fail to establish VPN connections. In some cases, bypass users may connect intermittently.

Workaround:

Update the Duo OpenVPN client version on the gateway by modifying the version in the duo_openvpn.py file from 2.4 to 3.0.

AVX-74226

CoPilot deployments and migrations may fail with "Unsupported instance size" errors when selecting valid instance types. The instance type validation incorrectly blocks supported sizes during CoPilot deployment or migration operations.

Impact:

CoPilot deployment or migration may fail when selecting certain valid instance types

Error message "Unsupported instance size" is displayed even for supported sizes

Workaround:

Contact Aviatrix Support for assistance with CoPilot deployment using the affected instance types.

AVX-74465

Aviatrix HPE gateway (including HA gateway) creation failed in OCI VCNs with DNS disabled. Gateways can now be created regardless of VCN DNS configuration.

Workaround:

Contact Aviatrix Support for assistance.

AVX-74577

Users are unable to modify tags on third-party firewall instances when those tags contain values with multiple colons (for example, team:iac:module.version:v1.5.3). Attempts to update tags after deployment fail with a too many values to unpack error. Initial deployment is unaffected because tags are passed via a different code path during creation.

Impact:

  • Third-party firewall instance tag updates fail when tag values contain multiple colons

  • Initial deployment with multi-colon tags is not affected

Workaround:

Avoid using multiple colons in tag values when modifying tags after deployment. Use alternative delimiters such as hyphens or underscores.

AVX-76132

Unable to configure more than one OpenVPN gateway behind a UDP Load Balancer. Only the first gateway is retained while additional gateways are incorrectly excluded. This issue affects versions 6.9, 7.x, 8.x, and 9.0.0.

Impact:

  • Multi-gateway VPN deployments relying on UDP load balancing for redundancy or scale are affected.

  • No impact on single-gateway deployments or data plane traffic.

  • Existing multi-gateway configurations set up in 6.x continue to function after upgrading to 7.x or 8.x. Only new deployments or modifications to existing configurations are affected.

Workaround:

Contact Aviatrix Support for assistance in applying the workaround.

AVX-76413

Description: When the avx-ctrl-state-sync service starts up and finds gateways stored as "Down" in etcd, the controller reprograms the network as if those gateways are down, without allowing time for the gateways to connect and prove they are up. This can occur when the controller has previously lost connectivity to gateways (for example, during a transient network issue) and the service then restarts while the gateways themselves remain healthy and continue forwarding traffic.

Impact: A temporary dataplane disruption occurs while the controller has the gateways marked as down. The controller automatically detects the gateways are up and reprograms the network correctly immediately afterward. In a large-scale user deployment (~1,400 gateways), full recovery completed in approximately 6 minutes. The underlying behavior has existed for 4+ years and has been observed in a user environment only once.

Workaround: Not applicable. The system recovers automatically, no user action required. Recovery typically completes within minutes (~6 min observed in a ~1,400-gateway deployment; smaller deployments recover faster).

AVX-77135

When the Use SSL to connect option is enabled for LDAP configuration, VPN gateway configuration updates may not apply correctly.

Impact:

VPN gateway authentication using LDAP with TLS may not function as expected

Manual intervention may be required to ensure VPN authentication is properly configured

Workaround:

Contact Aviatrix Support for assistance.