Become a Beta Tester

Containers · Platform

Frabs for OpenVZ

On an OpenVZ host, Frabs lists the containers and watches each one's interface, or splits shared venet traffic by container address.

OpenVZ

Protects
OpenVZ containers
Recognised by
The vzctl tools or the vzkernel
Watches
veth<ctid>.<n> · venet0
Panel links
Not needed

How it works

How Frabs works on OpenVZ

  1. 01

    Install

    One command as root on the server. It reads the setup without changing anything.

  2. 02

    Recognise OpenVZ

    The vzctl tools or the vzkernel tells the sensor which platform it is on.

  3. 03

    Find every guest

    vzlist -a -j.

  4. 04

    You confirm

    You review what it will watch. Protection starts within 30 seconds of confirming.

Networking

What it watches, and what it leaves alone

veth<ctid>.<n>

Containers with their own veth device

venet0

Shared by venet containers; traffic is split by each container's address

Bridges. The bridges containers attach to. Bridges with no containers are left alone.

How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.

An example plan

PlatformOpenVZ
Watchesveth204.0, …
Leaves aloneBridges with no guests
Changes madeNone until you act

Get started

Install on OpenVZ

On the server, as root

curl -fsSL https://install.frabs.net | sh -s -- --token frb_...

Questions

Is anything installed inside the containers?
No. The sensor runs on the server itself, never inside a customer's guest.
Does Frabs change my bridges or firewall?
No. It counts traffic in its own nftables table on each guest interface, and only acts when your rules or your team say so.
What happens if I add a bridge or move guests?
The server's page shows that the layout changed. Run frabs reconnect, review the updated plan and confirm.
What if the sensor stops?
Its network changes are removed and traffic carries on, unless you chose fail-closed.