Using FluxVM with Ragnarok
Ragnarok is the primary product UI/API that consumes FluxVM’s Kubernetes path (DisposableVm + fluxvm-kube). FluxVM stays a focused VM engine; Ragnarok is the operator console, RBAC, and SSO layer on top.
Roles
| Layer | Owns |
|---|---|
| FluxVM | QEMU / Cloud Hypervisor / Firecracker VMs, TTL reaper, fluxctl serve, DisposableVm CRD + node DaemonSet |
| Ragnarok | KubeVirt fleet + FluxVM Hub UI/API, JWT/OIDC/LDAP auth, RBAC, audit |
Ragnarok never calls fluxctl serve over the host REST API from the product path — it creates/reads/deletes DisposableVm CRs and lets the per-node operator talk to a local fluxctl serve.
Install order (user / lab)
-
Optional — Ragnarok binary trial (proprietary; FluxVM stays free):
VER=0.5.1curl -LO "https://github.com/zyvorai/fluxvm/releases/download/ragnarok-v${VER}/ragnarok-${VER}-linux-amd64.tar.gz"tar xzf "ragnarok-${VER}-linux-amd64.tar.gz" && cd "ragnarok-${VER}-linux-amd64"ls -l trial.token # signed evaluation token — keep beside ./ragnarok./install.sh# edit ragnarok.env — then: set -a && source ragnarok.env && set +a && ./ragnarokcurl -s http://127.0.0.1:5010/api/v1/license/statusOr install Ragnarok via Helm /
deploy-remote.shfrom the private repo with--set license.key=<jwt>(same JWT astrial.token). After expiry: sales@zyvor.dev for a renewed token. -
FluxVM on capable nodes — see
deploy/k8s/in this repo (and Kubernetes deployment on the site):kubectl apply -f deploy/k8s/namespace.yamlkubectl apply -f deploy/k8s/crd.yamlkubectl apply -f deploy/k8s/rbac.yamlkubectl apply -f deploy/k8s/daemonset.yamlkubectl label node <node> ragnarok.io/fluxvm-capable=true# Stage VM images under the DaemonSet state_dir hostPath on each node -
Ragnarok — install KubeVirt first, then Ragnarok (Helm / Kustomize /
./scripts/deploy-remote.sh). Docs:- Technical: zyvor.dev Ragnarok docs
- User manual: Ragnarok manual
- OIDC/SSO: Ragnarok repo
docs/OIDC.mdand deploy--with-oidc(IdP proxy is Ragnarok’s concern; FluxVM does not terminate SSO)
-
Open Ragnarok UI → FluxVM VMs (or Confidential / FluxVM Hub). If the operator is missing, Ragnarok shows an explicit “operator not detected” banner instead of a silent empty list.
What Ragnarok adds
GET /api/v1/fluxvm/capability— CRD present?GET /api/v1/fluxvm/nodes— nodes labeledragnarok.io/fluxvm-capable=true- CRUD under
/api/v1/fluxvm/vms— namespace-scoped to the caller’s RBAC
No Ragnarok-specific CRD fields: anything you can kubectl apply as a DisposableVm, Ragnarok can create.
User manuals (published)
| Product | Manual |
|---|---|
| FluxVM | https://zyvor.dev/docs/fluxvm-manual |
| Ragnarok | https://zyvor.dev/docs/ragnarok-manual |
| Suite index | https://zyvor.dev/docs/user-manuals |
Auth note
FluxVM is free (Apache-2.0) — no Ragnarok license token applies to it.
SSO (Keycloak OIDC), local break-glass, LDAP, and the Ragnarok signed
trial.token / commercial JWT live entirely in Ragnarok (proprietary).
FluxVM’s own REST API uses optional bearer tokens for direct fluxctl serve
callers; that is separate from the Ragnarok dashboard login and from Ragnarok
trial tokens (scripts/trial-tool.py stays in the private Ragnarok repo only).
See also zyvor-fabric.md for the other primary FluxVM integration.