Become a Beta Tester

Containers · Platform

Frabs for LXC

On a classic LXC host, Frabs lists the containers and watches each container's veth interface.

LXC

Protects
LXC containers
Recognised by
The lxc tools, when LXD and Incus are not installed
Watches
veth…
Panel links
Not needed

How it works

How Frabs works on LXC

  1. 01

    Install

    One command as root on the server. It reads the setup without changing anything.

  2. 02

    Recognise LXC

    The lxc tools, when LXD and Incus are not installed tells the sensor which platform it is on.

  3. 03

    Find every guest

    lxc-ls and lxc-info for each container's interfaces and addresses.

  4. 04

    You confirm

    You review what it will watch. Protection starts within 30 seconds of confirming.

Networking

What it watches, and what it leaves alone

veth…

The host side of each container's network device

Bridges. The bridge the containers attach to, such as lxcbr0.

How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.

An example plan

PlatformLXC
Watchesveth…, …
Leaves aloneBridges with no guests
Changes madeNone until you act

Get started

Install on LXC

On the server, as root

curl -fsSL https://install.frabs.net | sh -s -- --token frb_...

Questions

Is anything installed inside the containers?
No. The sensor runs on the server itself, never inside a customer's guest.
Does Frabs change my bridges or firewall?
No. It counts traffic in its own nftables table on each guest interface, and only acts when your rules or your team say so.
What happens if I add a bridge or move guests?
The server's page shows that the layout changed. Run frabs reconnect, review the updated plan and confirm.
What if the sensor stops?
Its network changes are removed and traffic carries on, unless you chose fail-closed.