Become a Beta Tester

Containers · Platform

Frabs for LXD

On an LXD host, Frabs lists instances through LXD and watches each one's host-side interface.

LXD

Protects
LXD containers and VMs
Recognised by
The lxd package
Watches
veth…
Panel links
Not needed

How it works

How Frabs works on LXD

  1. 01

    Install

    One command as root on the server. It reads the setup without changing anything.

  2. 02

    Recognise LXD

    The lxd package tells the sensor which platform it is on.

  3. 03

    Find every guest

    lxc list --format json.

  4. 04

    You confirm

    You review what it will watch. Protection starts within 30 seconds of confirming.

Networking

What it watches, and what it leaves alone

veth…

The host side of each instance's network device

Bridges. The bridge your instances use, such as lxdbr0.

How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.

An example plan

PlatformLXD
Watchesveth…, …
Leaves aloneBridges with no guests
Changes madeNone until you act

Get started

Install on LXD

On the server, as root

curl -fsSL https://install.frabs.net | sh -s -- --token frb_...

Questions

Is anything installed inside the containers?
No. The sensor runs on the server itself, never inside a customer's guest.
Does Frabs change my bridges or firewall?
No. It counts traffic in its own nftables table on each guest interface, and only acts when your rules or your team say so.
What happens if I add a bridge or move guests?
The server's page shows that the layout changed. Run frabs reconnect, review the updated plan and confirm.
What if the sensor stops?
Its network changes are removed and traffic carries on, unless you chose fail-closed.