Skip to main content

Admin basics

Operate FluxVM on a host: service, ports, auth, logs, and production gates.

Service​

sudo systemctl enable --now fluxvm # if unit installed by deploy
# or foreground:
sudo fluxctl --config /etc/fluxvm.toml serve

TTL reaper and warm-pool backfill run only while serve is up.

Host dependencies​

./scripts/bootstrap-host.sh
# Windows offline customize needs libhivex + nbd:
sudo modprobe nbd max_part=16

Remote: ./scripts/deploy-remote.sh USER@HOST.

Ports​

PortRole
7788FluxVM REST (fluxctl serve)
9108Optional MicroVM Prometheus (MICROVM_METRICS_ADDR)

Fabric (separate product) typically listens on 9095 and proxies FluxVM.

Health​

curl -sf http://127.0.0.1:7788/healthz
curl -sf http://127.0.0.1:7788/readyz | jq .

Both are auth-exempt. Use /readyz when dataplane must be ready before work.

Auth (opt-in)​

Default: open API (every request is admin). Before exposing beyond localhost:

[auth]
require = true

[[auth.tokens]]
token = "replace-me"
role = "admin"
name = "ops"
# tenant = "team-a" # optional scope
curl -sf -H "Authorization: Bearer replace-me" http://127.0.0.1:7788/v1/vms

List/filter: GET /v1/vms?tenant=team-a. See PRODUCTION.md and SECURITY.md.

State and logs​

PathRole
<state_dir>/vms.jsonVM inventory (flock via vms.lock)
<state_dir>/instances/<uuid>/console.logPer-VM console
<state_dir>/instances/<uuid>/serial.sockQEMU serial socket (fluxctl serial)
<state_dir>/instances/<uuid>/disks/QEMU data disks (fluxctl disk)
<state_dir>/events.jsonlLifecycle/audit events (fluxctl events)
<state_dir>/vm-templates.jsonVM templates (fluxctl vm-template)
<state_dir>/backups/VM backups (fluxctl backup)
journalctl -u fluxvm -fDaemon journal

Production checklist​

./scripts/release-checklist.sh