Become a Beta Tester

KVM · Platform

Frabs for libvirt / KVM

For plain KVM hosts and panels built on libvirt, Frabs reads the VMs over a read-only libvirt connection.

libvirt / KVM

Protects
KVM virtual machines managed by libvirt
Recognised by
The libvirt daemon, when no hosting panel is found
Watches
vnet<n>
Panel links
Not needed

How it works

How Frabs works on libvirt / KVM

  1. 01

    Install

    One command as root on the server. It reads the setup without changing anything.

  2. 02

    Recognise libvirt / KVM

    The libvirt daemon, when no hosting panel is found tells the sensor which platform it is on.

  3. 03

    Find every guest

    A read-only libvirt connection: virsh list, domstate and domiflist.

  4. 04

    You confirm

    You review what it will watch. Protection starts within 30 seconds of confirming.

Networking

What it watches, and what it leaves alone

vnet<n>

libvirt's default naming for VM interfaces

Bridges. The Linux bridges or networks your VMs use. Bridges with no VMs are left alone.

How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.

An example plan

Platformlibvirt / KVM
Watchesvnet0, …
Leaves aloneBridges with no guests
Changes madeNone until you act

Get started

Install on libvirt / KVM

On the server, as root

curl -fsSL https://install.frabs.net | sh -s -- --token frb_...

Questions

Is anything installed inside the VMs?
No. The sensor runs on the server itself, never inside a customer's guest.
Does Frabs change my bridges or firewall?
No. It counts traffic in its own nftables table on each guest interface, and only acts when your rules or your team say so.
What happens if I add a bridge or move guests?
The server's page shows that the layout changed. Run frabs reconnect, review the updated plan and confirm.
What if the sensor stops?
Its network changes are removed and traffic carries on, unless you chose fail-closed.