Skip to main content

Tiny Windows on FluxVM

Lightweight Windows guests (Tiny11, Tiny11 Core, Tiny10) run on the QEMU backend only. Use OVMF for UEFI disks. Do not combine Linux cloud_init fields with a windows{} block.

Preferred golden path: build via sibling Kryton (VERSION=tiny11), then customize here — see windows-golden.md. Bring-your-own VHDX still works for quick labs.

Host​

sudo ./scripts/bootstrap-host.sh

Typical firmware path on RHEL-family hosts: /usr/share/OVMF/OVMF_CODE.fd.

Need: QEMU/KVM, OVMF, qemu-img, virtio-win drivers, hivex/libhivex, and GuestKit built with registry-write + agent.

# Clone kryton next to fluxvm, then (~45–90m first time):
./scripts/prepare-windows-golden.sh --build --version tiny11 --image-id windows-tiny11

# Installs: /var/lib/fluxvm/images/windows-tiny11-golden.qcow2

Point examples/build-image-tiny11.json source at that path (or symlink tiny11-base.qcow2 → the golden).

Disk (BYO VHDX)​

qemu-img convert -O qcow2 tiny11.vhdx /var/lib/fluxvm/images/tiny11-base.qcow2
guestkit doctor /var/lib/fluxvm/images/tiny11-base.qcow2 --target kvm --explain
guestkit plan apply virtio.yaml --vm /var/lib/fluxvm/images/tiny11-base.qcow2 --yes

Customize then boot​

sudo fluxctl --config /etc/fluxvm.toml build-image --spec examples/build-image-tiny11.json
sudo fluxctl --config /etc/fluxvm.toml create --spec examples/tiny11-qga.json
fluxctl list
fluxctl get <id>

RDP to host port 3389 (user-mode forward). For a known guest IP use examples/tiny11-tap.json after vmbr0 exists.

Live QGA​

fluxctl qga ping <id>
fluxctl qga powershell <id> -- 'hostname; Get-Content C:\fluxvm-ready.txt'

Smoke​

WINDOWS_IMAGE=/var/lib/fluxvm/images/windows-tiny11-golden.qcow2 \
sudo -E ./scripts/test-tiny11-windows.sh

Limits​

BackendWindows
QEMU + OVMF + QGASupported
Cloud HypervisorNot supported for this Tiny path (see ch-windows-qga.md)
Firecracker / flux-vm sandboxLinux kernel + raw rootfs only

Fabric​

zyvorai/fabric orchestrates FluxVM over REST. It does not implement the VMM. Tiny Windows must work in FluxVM first. A later Fabric PR should pass qga.enabled + OVMF and skip Linux cloud-init when the guest is Windows.

Tiny11 is unofficial. This tree does not ship ISOs or product keys — Kryton and dockur handle media when you build goldens yourself.