Skip to main content

DevOps runbooks — GuestKit

Operational docs for platform / migration / SRE teams who gate cutovers with GuestKit (doctor, migrate-plan, rescue, Passport) before hyper2kvm / HyperSDK convert.

RunbookWhen you need it
01 — Passport CI gateFail convert if score < floor — GitHub Actions: zyvorai/guestkit action
02 — Offline repair workerJump box / GHCR worker, root, NBD
03 — Air-gap packages & VirtIOMirror, cache, GUESTKIT_VIRTIO_WIN
04 — Fleet analyze at scaleDirectory of images, snowflakes
05 — Cutover weekendHour-by-hour ops checklist
06 — Failure triageDoctor red, BitLocker, GRUB, SAM
07 — Cloud disk sourcess3:// gs:// azure:// pulls + cache
08 — Forensic diff & IROffline drift / secrets / malware
09 — SBOM / inventory CISPDX/CycloneDX artifacts
10 — Rescue dry-run + SBOM diffAction extras, sbom-diff --fail-on-drift

Related: Wiki · Migration assurance · DOCKER / GHCR · Blogs: integrate pipeline · DevOps runbooks

Operating model​

RoleOwns
Migration / DevOpsWorker image, CI job, --fail-below, signing keys, mirror URL, change-ticket Passport attach
PlatformDisk staging (object store / NFS), runner privileges (qemu-nbd, loop), network to mirrors
App ownersAccept day-0 plans (RDP, SSH keys, domain leave), rotate temp passwords
Convert toolhyper2kvm / suite — only after passport verify green

Pin​

CLI: GitHub Release v1.2.5 # crates.io guestkit is still 0.3.2
Worker: ghcr.io/zyvorai/guestkit-worker # pin digest/tag in compose/Helm