Skip to main content

Kairon documentation

The root README is the product landing page. This docs/ tree is authoritative for install, runbooks, guides, and status detail.

Start here​

I want to…Read this
See the product landingRoot README
Install and run a first Machinegetting-started.md
Ten-minute architecture tour../ARCHITECTURE.md
Deep architecture referencearchitecture.md
Full feature inventoryWHAT_SHIPS.md
CLI referenceCLI.md
Dependency policyDEPENDENCIES.md
Release status & production gapsSTATUS.md
Hardware / lab matrixCOMPATIBILITY.md
Roadmap (v0.7 gates)../ROADMAP.md
Migration failures / NeedsRecoveryrunbook-migration-failures.md
Security / threat model../SECURITY.md
Contributing../CONTRIBUTING.md

Documentation map​

DocCovers
ARCHITECTURE.mdThe ten-minute tour: components, request flow, trust boundaries/deployment topology, design rationale
getting-started.mdInstall, first Machine, cold migrate, live migration, the dashboard, Network Fabric
tutorials/machine-lifecycle.mdNarrated walkthrough: one Machine through create → relocate → snapshot → restore
architecture.mdDeep reference: the cold/live migration state machines, session durability, CSI/DRA mechanics, operational visibility
migration-adapter.mdThe migration adapter HTTP contract, trust boundary, the real kairon-migration-adapter-fluxvm implementation
network-fabric.mdMachineNetworkPolicy/NetworkSecurityGroup, FluxVM eBPF edge, opt-in Cilium ExternalWorkload attach and CNP sync
ebpf-edge.mdVM edge enforced by FluxVM: anti-spoof, learn-IP, QoS, DNS/SNI allow lists, attributed drops and metrics, packet capture, conntrack move on live migration
tutorials/network-fabric.md · guides/machine-network.md · guides/network-policy.mdNetwork Fabric walkthrough and field-level guides
guides/machine-quotas.md · guides/machine-disruption-budgets.mdMachineQuota/MachineDisruptionBudget reference, including the admission webhook
runbook-migration-failures.mdDiagnosing and resolving NeedsRecovery, alert-to-runbook cross-references
guides/machine-fencing.mdNodeUnreachable/Fenced conditions, kaironctl fence's safety model, storage/network migration preflight labels
ai-agents.md · guides/hermes-mcp.mdAI agent integration over MCP (Hermes Agent, Claude Code, Cursor): Kairon and FluxVM servers, scoped credentials, workflows; kaironctl mcp serve reference
guides/kairon-ui-ha.mdRunning ui.replicaCount > 1: what's shared, how, and its real limits
guides/kairon-controller-ha.mdRunning controller.replicaCount > 1: Lease-based leader election, RBAC, bare-metal setup
guides/observability.mdWhat each component's /metrics exposes, the kairon-health alert group, and the renamed PrometheusRule
guides/machine-migration-tls.mdControl-plane vs. data-plane migration TLS, and real per-node data-plane identity via migration.dataplaneTlsSecretName
guides/kairon-ui-oidc.mdOIDC/SSO setup, the Authorization Code + PKCE flow, and why it breaks Go-stdlib-only
guides/kairon-ui-console-rbac.mdReal Kubernetes RBAC (machines/console + SubjectAccessReview) for console access, opt-in alongside the annotation allowlist
guides/machine-storage.md · guides/machine-storage-csi.mdPVC-backed boot disks; Kairon's own first-cut iSCSI CSI driver and why it breaks Go-stdlib-only
guides/machine-storage-atlas.mdspec.volumes[].atlas: controller provisions Machine disks through Atlas (PVC or raw RBD), gates scheduling on readiness, releases after runtime cleanup
guides/machine-storage-thirdparty-csi.mdnode.thirdPartyCSIDrivers: kairon-node as a generic CSI client against an allowlisted third-party driver, including attachRequired drivers (VolumeAttachment) and namespace-allowlisted node secrets
guides/migrate-from-vmware.mdMoving VMware VMs to Kairon: kaironctl import ova, offline virtio repair, checklist
guides/machine-image-import.mdspec.image.source: downloading a remote image URL into kairon-node's own digest-keyed cache
guides/machine-sets.mdMachineSet: replica reconciliation, RollingUpdate/Recreate rollout strategy
guides/machine-fork.mdkaironctl fork / fork_machine: live copies of a Running Machine from one memory snapshot
guides/machine-pools.mdMachinePool / MachineClaim: warm, pre-booted Machines claimed in one reconcile tick
guides/machine-instance-types.mdMachineInstanceType: a reusable named CPU/memory shape resolved into spec.resources once
guides/machine-cpu-numa.mdspec.resources.numaNode/.cpuSet/.hugepages: qemu-only NUMA/hugepage passthroughs, and what they don't guarantee (no real host-core pinning)
guides/machine-cpu-pinning.mdspec.resources.cpuPinning: real exclusive host-core allocation, and the operator-asserted pinnable-cpus node label it depends on
guides/machine-windows-guests.mdWhat Windows guest support covers today (legacy-BIOS + cloudbase-init, and now UEFI Secure Boot/vTPM for Windows 11 given a node-configured OVMF vars template)
guides/migration-policies.mdMigrationPolicy: selector-scoped migration bandwidth defaulting and concurrency caps
guides/machine-snapshot-quiesce.mdReal guest fsfreeze/fsthaw around MachineSnapshot, and the controller↔node coordination protocol behind it
guides/machine-backup.mdFull disk backups with guest fsfreeze (MachineBackup) through FluxVM or Atlas S3, and in-place restore (MachineBackupRestore)
guides/machine-snapshot-restore.mdRestoring a MachineSnapshot volume into a new PersistentVolumeClaim via the standard CSI dataSource flow
guides/machine-pause-resume.md · guides/machine-halt.mdspec.powerState: Paused/Halted: suspending guest CPUs vs. powering off the VMM process while FluxVM keeps its record
guides/machine-hotplug.mdGrowing spec.resources.cpu/.memory, and hot-attaching PVC disks (spec.disks) and extra NICs (spec.network.extraInterfaces) on a Running Machine
guides/machine-resource-limits.mdspec.resources.limits: real, kernel-enforced cgroup v2 caps, and status.resourceUsage live usage
guides/machine-placement.mdScheduler internals: affinity/anti-affinity, weighted soft scoring, topologySpreadConstraints, DRA topology hints
guides/machine-sriov.mdSR-IOV NIC passthrough by reusing the existing GPU/VFIO DRA mechanism — why Multus doesn't apply to Kairon Machines at all
guides/machine-guest-agent.mdspec.guestAgent: real qemu-guest-agent-reported status.guestIP, including user/SLIRP networking
guides/machine-guest-exec.mdGuest exec (qemu-guest-agent), and the smaller API-only fsfreeze-status/firewall endpoints alongside it
guides/machine-guest-agent-files.mdGuest file access and the backend-agnostic vsock-agent guest exec, both over spec.guestAgent.console
guides/machine-text-console.mdInteractive in-browser text console over FluxVM's own proprietary vsock guest agent
guides/machine-logs.mdStreaming a Machine's real captured serial console output -- Kairon's kubectl logs/-f equivalent
guides/machine-vm-state-snapshot.mdFull hypervisor-level VM-state checkpoint/restore (RAM, CPU, device state) -- distinct from MachineSnapshot's disk-content-only CSI snapshot
guides/machine-sandboxes.mdspec.sandbox: FluxVM's lightweight agent-sandbox track, templates, the HTTP proxy relay, warm pools, and the egress check
guides/machine-image-catalog.mdspec.image.catalogName: FluxVM's node-local, checksummed image catalog and its admin API
guides/machine-diagnostics.mdRuntime capabilities, PSI pressure, effective CPU set, and cgroup-level freeze/thaw
guides/crd-versioning.mdWhat a real CRD version bump (v1beta1) still requires; the conversion webhook scaffold that exists today
runbook-multi-host-migration-test.md · runbook-recovery-drill.mdReal two-host live-migration testing; deliberately drilling a NeedsRecovery recovery
runbook-backup-restore.mdBacking up/restoring Kairon's CRD state (scripts/backup-crds.sh/restore-crds.sh), and what it doesn't cover (VM disk content, FluxVM host state)
runbook-velero-backup.mdUsing generic Velero (no Kairon-specific plugin) instead — what works out of the box, and the one real gap (no disk-content snapshot without a real CSI storage backend)
runbook-vm-export.mdGetting a Machine's disk content out of the cluster entirely, with standard Kubernetes primitives (no new Kairon-specific export tooling)
design-cluster-api-provider.mdScoped, not built: what a real Cluster API infrastructure provider would take, and the real ownerReferences gap that blocks it today
ROADMAP.md · RELEASE_NOTES.mdWhat shipped per version, what's next; per-release changelog
SECURITY.mdThreat model, vulnerability reporting
CONTRIBUTING.mdPR checklist, coverage floor, frontend checks

Also in this tree​

DocCovers
guides/relocating-a-machine.mdCold/live migrate, evacuate, enable mTLS, cancel/delete/quiesce behavior
guides/admission-webhook.mdEnabling the ValidatingWebhook for quotas/budgets (README “Guarding the fleet”)
WHAT_SHIPS.mdFull feature inventory (was README “What ships today”)
CLI.mdFull kaironctl / kubectl kairon command reference (Cobra, embedded Helm, Krew)
DEPENDENCIES.mdStdlib-only controller/node vs named exceptions (CLI Helm, OIDC, CSI)
STATUS.mdv0.6.0 status + production gaps