Admin basics
Operate FluxVM on a host: service, ports, auth, logs, and production gates.
Service
sudo systemctl enable --now fluxvm # if unit installed by deploy
# or foreground:
sudo fluxctl --config /etc/fluxvm.toml serve
TTL reaper and warm-pool backfill run only while serve is up.
Host dependencies
./scripts/bootstrap-host.sh
# Windows offline customize needs libhivex + nbd:
sudo modprobe nbd max_part=16
Remote: ./scripts/deploy-remote.sh USER@HOST.
Ports
| Port | Role |
|---|---|
| 7788 | FluxVM REST (fluxctl serve) |
| 9108 | Optional MicroVM Prometheus (MICROVM_METRICS_ADDR) |
Fabric (separate product) typically listens on 9095 and proxies FluxVM.
Health
curl -sf http://127.0.0.1:7788/healthz
curl -sf http://127.0.0.1:7788/readyz | jq .
Both are auth-exempt. Use /readyz when dataplane must be ready before work.
Auth (opt-in)
Default: open API (every request is admin). Before exposing beyond localhost:
[auth]
require = true
[[auth.tokens]]
token = "replace-me"
role = "admin"
name = "ops"
# tenant = "team-a" # optional scope
curl -sf -H "Authorization: Bearer replace-me" http://127.0.0.1:7788/v1/vms
List/filter: GET /v1/vms?tenant=team-a. See PRODUCTION.md
and SECURITY.md.
State and logs
| Path | Role |
|---|---|
<state_dir>/vms.json | VM inventory (flock via vms.lock) |
<state_dir>/instances/<uuid>/console.log | Per-VM console |
<state_dir>/instances/<uuid>/serial.sock | QEMU serial socket (fluxctl serial) |
<state_dir>/instances/<uuid>/disks/ | QEMU data disks (fluxctl disk) |
<state_dir>/events.jsonl | Lifecycle/audit events (fluxctl events) |
<state_dir>/vm-templates.json | VM templates (fluxctl vm-template) |
<state_dir>/backups/ | VM backups (fluxctl backup) |
journalctl -u fluxvm -f | Daemon journal |
Production checklist
./scripts/release-checklist.sh