KVM · Platform
Frabs for VirtFusion
On a VirtFusion hypervisor, Frabs reads the VMs through a read-only libvirt connection and watches each VM's interface.

VirtFusion
- Protects
- KVM virtual machines
- Recognised by
- The virtfusion package
- Watches
- Each VM's tap device
- Panel links
- Open in VirtFusion
How it works
How Frabs works on VirtFusion
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise VirtFusion
The virtfusion package tells the sensor which platform it is on.
- 03
Find every guest
A read-only libvirt connection: virsh list and domiflist.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
Each VM's tap device
As libvirt reports it for the VM, often vnet<n>
Bridges. The bridges your VMs attach to. Bridges with no VMs are left alone.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on VirtFusion
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- Install on each hypervisor, not the VirtFusion control server
- VM pages link straight to the VM: Open in VirtFusion
- Read the Install Guide
Questions
Is anything installed inside the VMs?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported