Containers · Platform
Frabs for OpenVZ
On an OpenVZ host, Frabs lists the containers and watches each one's interface, or splits shared venet traffic by container address.

OpenVZ
- Protects
- OpenVZ containers
- Recognised by
- The vzctl tools or the vzkernel
- Watches
- veth<ctid>.<n> · venet0
- Panel links
- Not needed
How it works
How Frabs works on OpenVZ
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise OpenVZ
The vzctl tools or the vzkernel tells the sensor which platform it is on.
- 03
Find every guest
vzlist -a -j.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
veth<ctid>.<n>
Containers with their own veth device
venet0
Shared by venet containers; traffic is split by each container's address
Bridges. The bridges containers attach to. Bridges with no containers are left alone.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on OpenVZ
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- venet containers are told apart by address, so keep their addresses unique
- Read the Install Guide
Questions
Is anything installed inside the containers?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported