Containers · Platform
Frabs for Incus
On an Incus host, Frabs lists instances through Incus and watches each one's host-side interface.

Incus
- Protects
- Incus containers and VMs
- Recognised by
- The incus package
- Watches
- veth…
- Panel links
- Not needed
How it works
How Frabs works on Incus
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise Incus
The incus package tells the sensor which platform it is on.
- 03
Find every guest
incus list --format json.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
veth…
The host side of each instance's network device
Bridges. The bridge your instances use, such as incusbr0.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on Incus
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- Install on each Incus cluster member
- Read the Install Guide
Questions
Is anything installed inside the containers?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported