KVM · Platform
Frabs for Virtualizor
On a Virtualizor server, Frabs reads the KVM guests through libvirt and the containers through vzlist, then watches each one's interface.
Virtualizor
- Protects
- KVM virtual machines, and OpenVZ containers where you run them
- Recognised by
- The virtualizor package
- Watches
- viif<n>
- Panel links
- Open in Virtualizor
How it works
How Frabs works on Virtualizor
- 01
Install
One command as root on the server. It reads the setup without changing anything.
- 02
Recognise Virtualizor
The virtualizor package tells the sensor which platform it is on.
- 03
Find every guest
A read-only libvirt connection: virsh list and domiflist for each VM's interfaces. vzlist, where the server runs containers.
- 04
You confirm
You review what it will watch. Protection starts within 30 seconds of confirming.
Networking
What it watches, and what it leaves alone
viif<n>
Virtualizor's naming for VM interfaces, for example viif3
Bridges. The bridge Virtualizor uses for VMs, such as viifbr0. Bridges with no guests are left alone.
How traffic is counted. A Frabs-only nftables table on each guest interface. Your own firewall rules and the host's interfaces are not touched, and nothing changes until a rule or a person acts.
An example plan
Get started
Install on Virtualizor
On the server, as root
curl -fsSL https://install.frabs.net | sh -s -- --token frb_...
- Install on each Virtualizor slave server
- libvirt is opened read-only; nothing in Virtualizor is changed
- VM pages link straight to the VM: Open in Virtualizor
- Read the Install Guide
Questions
Is anything installed inside the VMs?
Does Frabs change my bridges or firewall?
What happens if I add a bridge or move guests?
What if the sensor stops?
Also supported