Skip to main content

Zyvor Fabric

Private cloud control plane for Linux.
See how it stacks up.

Fabric vs Proxmox, OpenStack and libvirt — then Keep and FluxVM for the agent stack you run yourself.

  • 1~15 MB Rust daemon
  • 3open layers, one stack
  • 0egress connects, on stage

The matrix

Side by side.

Start with Fabric vs the field. Switch tabs for Muse vs the Keep stack, or FluxVM vs libvirt.

Fabric compared with Proxmox VE, OpenStack and libvirt on capabilities.
Fabriccontrol planeProxmox VEOpenStacklibvirt / virsh
Platform
Single binarySupported: YesNot offered: NoNot offered: NoNot applicable: N/A
REST APISupported: YesSupported: YesSupported: YesPartial or with caveats: XML-RPC
Web UISupported: YesSupported: YesSupported: Yes (Horizon)Not offered: No
CLISupported: YesSupported: YesSupported: YesSupported: Yes
Kubernetes operatorSupported: YesNot offered: NoSupported: YesNot offered: No
Terraform providerSupported: YesSupported: YesSupported: YesSupported: Yes
Networking
Network policiesSupported: Cilium-stylePartial or with caveats: BasicSupported: NeutronNot offered: No
Service meshSupported: YesNot offered: NoNot offered: NoNot offered: No
VPN meshSupported: WireGuardNot offered: NoNot offered: NoNot offered: No
GPU passthroughSupported: YesSupported: YesSupported: YesSupported: Yes
Operations
Live migrationSupported: Yes (disk-copy GA, native preview)Supported: YesSupported: YesSupported: Yes
Storage live migrationSupported: YesSupported: YesSupported: YesSupported: Yes
VM hibernateSupported: YesSupported: YesNot offered: NoSupported: Yes
VM importSupported: Yes (VMDK/VDI)Supported: YesPartial or with caveats: LimitedPartial or with caveats: qemu-img
Identity & audit
LDAP / OIDC SSOSupported: YesSupported: YesSupported: Yes (Keystone)Not offered: No
Multi-tenancySupported: YesSupported: YesSupported: YesNot offered: No
RBACSupported: 3-tierSupported: 3-tierSupported: KeystoneNot offered: No
Audit loggingSupported: YesSupported: YesSupported: YesNot offered: No
Project
Written inSupported: RustSupported: Perl / CSupported: PythonSupported: C
LicenseSupported: Apache-2.0Partial or with caveats: AGPLSupported: Apache-2.0Partial or with caveats: LGPL

Capability rows from the product overview. The other columns are Zyvor’s reading of those projects — check their docs before you decide.

What Muse got right

Same threat model. Credit where due.

Muse’s public story gets the shape right. Keep starts from the same five ideas.

  • One computer per personA persistent Linux box, not a chat session.
  • Two domainsUntrusted agent cell vs host-side authority.
  • Surrogate secretsThe agent never holds the real password.
  • Capability approvalsBound to a connector, not a sentence in chat.
  • Accessibility-tree browserThe driver sees refs, not raw DOM + JS.

The stack

One outsider. Three layers you own.

Keep, Fabric and FluxVM aren’t rivals — they’re one stack. Muse is the reference point outside it.

Outside your wallsMuseClosed personal agent on Meta’s cloud, as publicly described.
  1. KeepProduct layerPolicy, vault, approvals, browser, demos
  2. FabricControl planeConsole, JWT, Agents / Sessions
  3. FluxVMHypervisorThe cell + the host TC/eBPF pin

Security profiles

Three rungs. One says what it can’t prove.

Keep labels every cell with the evidence it actually has. Measured is software-test; hardware attestation stays gated until a verified run.

Evidence
software-test
Hardware attestation
Never
Can the host read it?
Yes — the host can still see a measured VM
What you may claim
A software-test measurement. Never hardware attestation.
attestation illustrative · field names from KEEP-0.2
profile: "measured"
image_hash: "(soft)"
evidence_class: "software-test"
snp_launch_verified: false
tdx_launch_verified: false
host_recover_allowed: true  // dual keys, audited
operator_can_read: true

Muse’s Secure VM is described as having the same limit today (public detail is thin). Keep states its limit here, in the product. Security profiles ›

Proof on stage

Don’t trust the story.
Read the counter.

The PDF-brief demo runs an agent through a vendor SOW behind a host-side eBPF pin — deny_udp plus gateway-only ports. It expects egress_connects: 0, read from Keep’s journal and FluxVM’s drop_reasons.

0
egress_connects
  • Keep audit journal
  • FluxVM host TC/eBPF pin

The cockpit

What you watch while it works.

A goal, its plan, the decisions the policy made, and the egress counter — with the honesty badge always on.

Scripted for illustration — real cockpit: /app/keep

Use cases

Not just a PDF.

Five packaged agents, three brokered-browser workflows and three workstation moves — every one under the same signed policy, in the same microVM cell.

Pack · pdf-brief

PDF in. brief.md out. Zero connects.

The one-click stage demo: drop a document on the cockpit and get a brief back, with no browser and nothing leaving the cell.

  1. Drop a PDF on /app/keep
  2. Agent reads it with pdftotext in the cell
  3. brief.md lands as an artifact
  • No browser
  • deny_udp + gateway-only ports
  • Expects egress_connects: 0
./scripts/keep-demo-pdf.sh examples/keep-agents/pdf-brief/sample.pdf

Produces brief.md

Tutorial 17 ›

Every run today reports software-test evidence — see the honesty band below.

Receipts

Run, archived, in the repo.

The pilot gate has passed on a real FluxVM host — happy path and deny path — with logs archived under docs/keep/pilot-runs/.

  • 2026-09-24 · 14:19 UTCsoftware-test

    Pilot gate

    template node22-agent

    • Happy path PASS
    • Deny path PASS
    20260924T141927Z ›
  • 2026-09-24 · 15:49 UTCsoftware-test

    Pilot gate

    template node22-agent

    • Happy path PASS
    • Deny path PASS
    20260924T154950Z ›
  • 2026-09-24 · 18:29 UTCsoftware-test

    Pilot gate on Firecracker

    template node22-fc

    • Happy path PASS
    • Deny path PASS
    • cell_backend=flux-vm
    • guest_worker=ok
    20260924T182930Z ›
  • 2026-09-24 · 19:09 UTCsoftware-test

    Browser screenshot lab proof

    template node22-agent

    • Tab listed via …/browser/view
    • Screenshot: HTTP 200, JPEG

    Lab stub (keep-cdp-stub) — no input takeover.

    20260924T190954Z ›

What the gate proves

Template required
Missing template → FAIL
Keep mode policy
Unsigned PUT refused; empty signers refuse start
Session + cockpit
evidence_class: software-test; restart recovers session
Out-of-band approval
Approve and deny paths; no unapproved mutate
Packaged agents
examples/keep-agents/ + goals and artifacts

Archived logs live in the repo; ./scripts/keep-pilot-gate.sh reruns the gate. Pilot runs ›

Roadmap

Shipped, gated, next.

What is done, what waits on hardware, and what comes after — straight from STATUS.md and the Keep 0.2 notes.

  1. ShippedFluxVM Phase 6
    • security_profile field
    • measured profile → software-test evidence
    FluxVM ›
  2. ShippedKeep 0.1 pilot
    • Live gate passed twice on a FluxVM host
    • Happy path and deny path
    Pilot runs ›
  3. ShippedKeep 0.1
    • BYO model socket, signed Sentinel policy
    • Phone approvals, pack / unpack
    • Cockpit, PDF brief, host eBPF pin
    Keep docs ›
  4. ShippedBrowser 0.3
    • Split-sight pause, vault-typed fill
    • Trajectory-as-code, goal-bound tabs
    • Origin taint lattice
    Browser 0.3 ›
  5. Gated on hardwareKeep 0.2
    • Soft scaffolding complete: attestation receipt, no host recover on confidential
    • Pending hardware: user-held unwrap, verified SNP/TDX flags
    Keep 0.2 ›
  6. NextBrowser 0.4 / 0.5
    • PacketWolf as an optional CONNECT 5-tuple observer
    • Signed site adapters (adapters/vcenter.yaml)
    • Confidential cells: CDP only via attested vsock
    Roadmap ›

Try it

Copy, paste, run.

Three commands from the repo. You need a FluxVM host; nothing here runs in Meta’s cloud.

One request: PDF in, brief.md out, and the script fails if anything connects out.

bash
export KEEP_API=http://127.0.0.1:9096
export KEEP_TOKEN=…   # agent-runtime token
./scripts/keep-demo-pdf.sh examples/keep-agents/pdf-brief/sample.pdf

Expect OK — brief.md ready, 0 CONNECT

  • A FluxVM host and agent-runtime (/healthz)
  • Template node22-agent with pdftotext (poppler)
  • Strict confinement: deny_udp + gateway-only ports
Tutorial 17 ›

Pick your layer

Use one. Use all three.

  • The agent workstation

    Keep

    • Signed policy that fails closed
    • Vault, approvals, brokered browser
    • pack / unpack to leave
    Keep docs ›
  • The control plane

    Fabric

    • 780+ endpoint REST API, one daemon
    • RBAC, audit, HA, live migration
    • CLI, console, K8s operator, Terraform
    Product overview ›
  • The hypervisor

    FluxVM

    • Firecracker, Cloud Hypervisor, QEMU/KVM
    • vsock agent — no SSH
    • TC/eBPF Network Fabric (GA)
    FluxVM on GitHub ›

Honesty

What we don’t claim yet.

  • Until Keep 0.2 runs on real SNP/TDX with a user-held key, evidence stays software-test — never “the operator cannot read this.” Muse’s Secure VM has the same limit today.
  • FluxVM’s multi-tenant controls are opt-in and are not a public-cloud boundary.
  • Muse details here are as publicly described; public detail is thin. Corrections welcome.

Run the open version.