We’re excited to announce the release of Portworx Enterprise 3.7.0 which includes multiple features across the release themes of operational efficiency, security and storage efficiency & resiliency. Read on to learn more about the features in the latest release of Portworx Enterprise.
Operational Efficiency
Platform teams are being asked to support more clusters, more workloads, and more environments without a proportional increase in headcount. Portworx reduces the operational surface area of running stateful Kubernetes at scale by automating provisioning, capacity management, and lifecycle tasks that would otherwise consume platform engineering time.
The business outcome is leverage: the same team supports more applications and more clusters, infrastructure is consumed more efficiently instead of being over-provisioned for safety, and time shifts from keeping the platform running to delivering services the business asked for.
What’s new in 3.7.0
KDS Day-2 Management: Lifecycle & KubeVirt Volume Provisioning
For customers standardizing VMs on KubeVirt, this feature turns Kube Datastore (KDS) into a first-class, lifecycle-managed storage construct rather than a one-off configuration, so operators can provision, scale, and retire KDS pools and VM volumes with consistent, repeatable workflows. It reduces operational risk and toil for Day-2 events (cluster expansion, tenant onboarding, maintenance) by aligning KDS management with the familiar “datastore” model VM teams already use in VMware, making KubeVirt adoption more predictable and easier to support at scale.
KDS Dynamic Pools: Faster Failover & Day-2 Operations
Dynamic Pools failover improvements cut over VM workloads faster when a node fails or is taken down for maintenance, by re-attaching the underlying FlashArray-backed pool instead of re-replicating data between nodes. This shortens VM outage windows, reduces the blast radius of hardware or OS failures, and enables more aggressive and predictable maintenance practices (patching, upgrades) without compromising the SLAs virtualization and application teams expect.
KDS Dynamic Pools: Expanded system limits
Empower enterprises to scale mission-critical Kubernetes and virtual machine workloads on a single cluster without storage bottlenecks. By supporting up to 4 dynamic pools with 100 Physical Volumes (PVs) each and up to 5,000 dynamic volumes per cluster, organizations can increase workload density and hardware consolidation while reducing the impact of fragmented storage silos. This increased headroom translates to lower operational overhead, simplified day-2 administration, and reduced total cost of ownership (TCO), enabling infrastructure teams to confidently expand their environment while preserving rapid pool failover and maximum backend SAN efficiency.
Tenant Kubernetes clusters on KubeVirt VMs with FlashArray Cloud Drives
Run tenant OpenShift clusters inside OpenShift Virtualization VMs. Portworx on the infrastructure cluster provisions the VM root disks from FlashArray cloud drives. This extends cloud drive automation to the VMs hosting each Kubernetes cluster, so clusters can be stood up, scaled, and torn down with minimal manual storage provisioning.
Security
Data is where the consequences of a security failure land, and the storage layer is increasingly in scope for the same audits, regulatory frameworks, and zero-trust mandates that govern the rest of the stack. Portworx builds security into the data layer itself (access control, encryption, tenant isolation, and recoverability), so protection is enforced by the platform rather than dependent on every application team getting it right.
What’s new in 3.7.0
Node-scoped Portworx Service Listeners
By binding the PX service strictly to the node’s IP stack instead of more permissive listener behavior, this feature tightens the Portworx network surface area and reduces exposure to mis-routed or unauthorized traffic. Customers operating in regulated or security-sensitive environments gain a cleaner story for network segmentation and firewalling around Kubernetes storage traffic, making it easier to pass security reviews and to enforce “least privilege” connectivity policies.
SSL Verification for FlashArray Connections
Enabling strict SSL verification on PXE–FlashArray connections ensures that Portworx nodes validate the identity of the array endpoints they talk to, closing off downgrade or man-in-the-middle classes of risk on the storage control path. For customers, this means they can adopt Portworx in environments that require strong TLS hygiene (custom CAs, certificate validation, audited trust chains) without workarounds, aligning Kubernetes storage operations with their corporate security and compliance standards.
Storage Efficiency & Resiliency
Portworx delivers storage efficiency by pooling and thin-provisioning capacity across any underlying block storage, so teams provision volumes on demand instead of over-buying. Automatic capacity expansion keeps utilization high as Kubernetes workloads scale. On the resiliency side, synchronous replication, automated failover, and application-consistent snapshots and backups keep stateful applications available through node, rack, or site failures, meeting recovery objectives without manual intervention.
What’s new in 3.7.0
Write-Zero Support for PX-RAW-Block [EA]
Write-zero support for PX-RAW-Block enables better integration with array-side thin provisioning and data-reduction workflows when block devices are wiped or re-initialized, so capacity accounting on the backend stays accurate over time. Practically, this reduces “phantom usage” on FlashArray for raw-block workloads and makes it safer for customers to reuse large raw devices (for databases, analytics engines, or VM images) without slowly leaking expensive array capacity.
Thin-Trim to Reclaim Deleted Space on FlashArray
The thin-trim feature enables PX-StoreV2 pools to issue discard operations back to FlashArray for volumes that have already been deleted in Portworx, reclaiming space that previously required ad-hoc “thin-trim scripts” and manual runbooks. Customers running large, high-churn workloads (e.g., ephemeral VMs or CI/CD environments) can now keep SAN capacity in line with actual data usage with a documented, upgrade-safe mechanism, which lowers storage costs and reduces the operational risk of one-off maintenance procedures.
Block In-Flight I/O During StoreV2 Pool Resize
Blocking in-flight I/O when resizing PX-StoreV2 pools ensures that expansion operations see a consistent view of data and metadata, rather than racing against live writes. For customers, this translates to safer, more predictable pool growth in production. Platform teams can add capacity to busy clusters with much lower risk of transient I/O errors, filesystem issues, or brittle “don’t resize while busy” scheduling rules.
Auto-Cordon for PX-StoreV2
Auto-cordon automatically marks nodes or pools as unschedulable for new workloads when their StoreV2 health falls outside safe thresholds, instead of relying on humans to constantly watch metrics and react. This prevents new pods or volumes from being placed on unhealthy capacity, reducing the chance of cascading failures and improving the overall incident “blast radius” when a node, pool, or disk experiences trouble.
Cloudsnap Health Enhancements
Cloudsnap health improvements roll up a set of customer-driven fixes and enhancements that make backup jobs more reliable and observable, covering failure handling, status reporting, and edge-case behaviors at scale. Customers relying on object-store backups get fewer failed or “stuck” backups and clearer diagnostics when something does go wrong, which shortens time-to-resolution for SREs and increases confidence that restores will work when they’re needed most.
Next Steps
- Learn more about Portworx 3.7.0 in the Release Notes.
- Sign up for a Hands-on Lab (live or self-paced)