Skip to main content

Using FluxVM in DevOps

FluxVM is the sibling engine under zyvorai/fabric. Platform pipelines should:

  1. Bootstrap the host (scripts/bootstrap-host.sh — KVM, nbd, dirs).
  2. Run fluxctl serve.
  3. Gate on GET /healthz (alive) and GET /readyz (state dir + dataplane when required).
  4. Let Fabric (or fluxctl create --spec) be the only writer.

Probes​

PathAuthReady meaning
/healthznoprocess up ({"ok": true})
/readyznook + optional kvm, state_dir, dataplane; HTTP 503 when not ready

Fabric GET /readyz nests this body under fluxvm and will stay 503 until this endpoint is 200.

See contracts/fabric-fluxvm-readyz.json.

CI​

Portable gates (GitHub-hosted runners, no nested KVM):

WorkflowWhenWhat
.github/workflows/ci.ymlevery PR + mainworkspace build/test, explicit virtio-vsock CSM units, MicroVM gates, image-customize matrix
.github/workflows/devops-gates.ymlevery PR + mainFabric contract/examples, offline devops-gate, upgrade-snapshot dry-run
.github/workflows/network-fabric.ymlpath-filteredeBPF build, fabric preflight/enable dry-run, workspace tests; opt-in TC/XDP smoke
.github/workflows/all-features.ymlpush to main + workflow_dispatchumbrella of portable suites (vsock, fabric, devops, SC units + use-case matrix, Sentinel/intelligence static)
.github/workflows/secure-containers.ymlpath-filteredSC crate fmt/unit/release build
.github/workflows/secure-containers-coverage.ymlpath-filtereduse-case matrix SoT lint + SC/NP/eBPF portable coverage

Live KVM / privileged BPF / multi-node stays on self-hosted runners and stays off until the matching repo variable is set (Settings → Variables).

Repo variables (vars.*)​

VariableEffect
FLUXVM_EBPF_PRIVILEGED_CI=1Privileged BPF host steps on GitHub-hosted ubuntu (Network Fabric smoke, AF_XDP, XDP/TCP, VMM guard, topology, memprof, quiclb, scx, flight-recorder)
FLUXVM_SECURE_CONTAINERS_LIVE_CI=1Live Secure Containers jobs on fluxvm-lab
FLUXVM_REQUIRE_MULTI_NODE=1Multi-node NetworkPolicy live job
FLUXVM_SECOND_CNI_GATE / FLUXVM_KATA_GATE / FLUXVM_REAL_FLEET_GATE / FLUXVM_ATTACHED_MIGRATION_GATESet19 fail-hard GA command strings
FLUXVM_LAB_KUBECONFIG / FLUXVM_RUNTIMECLASSLab kubeconfig / RuntimeClass for live SC
FLUXVM_SENTINEL_PRIVILEGED_CI=1Sentinel GA failure-injection on fluxvm-sentinel-lab
FLUXVM_UPGRADE_DESTRUCTIVE_E2E=1Upgrade-manager bpffs round-trip on fluxvm-ebpf-lab
FLUXVM_MIGRATION_PRIVILEGED_CI=1 (+ FLUXVM_MIGRATION_TEST_PLAN)Migration orchestrator lab
FLUXVM_FLEET_E2E=1Fleet rollout lab
FLUXVM_FLEET_GUARD_HOST_TEST=1 (+ FLUXVM_FLEET_GUARD_PLAN)Fleet guard host test

Self-hosted runner labels​

Label setUsed by
fluxvm-labSecure Containers live
fluxvm-ebpf-labSentinel upgrade-manager destructive E2E
fluxvm-sentinel-labSentinel GA certification privileged
fluxvm-migrationMigration orchestrator lab
fluxvm-fleet / fluxvm-fleet-labFleet guard / fleet rollout

Use-case matrix SoT: secure-containers-use-case-matrix.md (enforced by scripts/check-use-case-matrix.sh).

Lab smoke scripts (scripts/test-boot-smoke.sh, dataplane e2e) remain operator/self-hosted — not PR-gated on stock ubuntu.

Lab verify​

Easiest: ship the stack from sibling Fabric (or ./scripts/ship here):

./scripts/ship sus@HOST

Post-deploy lab pack on a KVM host (pairs with Fabric HTTPS :9095):

sudo -E ./scripts/test-lab-verify.sh
# covers: devops units + live devops-gate + upgrade-snapshot +
# four-tracks e2e + regression (readyz / KVM boot / sandbox / eBPF)

scripts/devops-gate.sh uses curl -k for Fabric self-signed TLS and auto-picks https://127.0.0.1:9095 when FABRIC_URL is unset.

Production readiness​

Read-only gate (Service Fabric schema/pins + Network Fabric health; optional VIP SLO):

FABRIC_URL=https://127.0.0.1:9095 FLUXVM_URL=http://127.0.0.1:7788 \
./scripts/test-production-readiness.sh

# with VIP latency / SLO
VIP=10.96.0.10 VIP_PORT=80 SERVICE=payments \
./scripts/test-production-readiness.sh

See PRODUCTION.md and service-fabric-phase6.md.

Kubernetes​

DaemonSet in deploy/k8s/ uses hostNetwork so Fabric on the same node can reach 127.0.0.1:7788. GitOps wrapper: deploy/k8s/gitops.

Upgrade with Fabric​

Snapshot FluxVM first, then Fabric:

sudo ./scripts/upgrade-snapshot.sh snapshot --tag before-$VERSION
# install fluxvm
./scripts/upgrade-snapshot.sh verify
# on the Fabric repo:
# sudo ./scripts/upgrade-rollback.sh snapshot --tag before-$VERSION

Examples: examples/devops/README.md.