Skip to main content

Zyvor Fabric Documentation Index

Complete documentation index for the Zyvor Fabric infrastructure control plane (Zyvor Fabric daemon).


Getting Started​

Guides for new users to install, configure, and begin using Zyvor Fabric.

DocumentDescription
Getting Started OverviewSection overview and reading order
Installation GuideSystem requirements, packages, building from source
Quick StartCreate your first VM in 5 minutes
Configuration ReferenceConfig file, environment variables, all sections
Web UI GuideDashboard access, login, VM management through browser

Tutorials​

Step-by-step walkthroughs for common workflows.

DocumentDescription
Tutorial indexFull numbered tutorial list
01 First VMCreate, configure, start, and connect to a virtual machine
02 NetworkingBridges, VLANs, bonds, port forwarding, network policies
03 Snapshots & BackupsSnapshots, backup policies, restore
04 Advanced VM optionsHotplug, start options, cloud-init
05 ClusteringDatacenters, pools, migration, HA (see also proven-infra limits)
06 Security hardeningAuth, RBAC, TLS, audit
07 Logging & complianceJournals, scans, secrets
08 OpenStack ClientsDrive Fabric with openstack CLI / curl (Keystone/Nova/…)
09 Edge dataplaneFluxVM Network Fabric via Fabric API / CLI / UI
15 AI WorkloadsOpenAI inference: Janus or NVIDIA, gateway, MIG (Beta)
16 Keep workstationKeep mode, signed policy, cockpit, browser
17 Keep PDF briefOne-click PDF → brief.md, 0 CONNECT
OpenStack Compatibility referenceEndpoints, public URL, limitations
Proven infrastructureCompatibility matrix, SLOs, chaos, upgrade/rollback (#14–#17)

Guides​

CLI Guides​

DocumentDescription
fabricctl ReferenceFull CLI command reference with examples
zyvor-fabricd-ctl OperationsDeployment, management, and maintenance commands
Declarative ConfigurationDefine VM infrastructure as YAML with fabricctl apply
Shell CompletionsEnable tab completion for bash

Operations Guides​

DocumentDescription
Production DeploymentHardening, TLS, monitoring, and logging for production
Capacity PlanningResource estimation and scaling guidelines
Backup StrategyBackup types, retention policies, and disaster recovery
Monitoring SetupPrometheus integration, alerting, and dashboards
TroubleshootingCommon issues, log analysis, and diagnostic steps
Upgrade ProceduresRolling upgrades and version migration
Security HardeningFirewall rules, RBAC policies, and credential rotation

Decision Support​

DocumentDescription
Zyvor Fabric vs. ProxmoxFeature and architecture comparison
Zyvor Fabric vs. OpenStackScope, complexity, and deployment comparison
Zyvor Fabric vs. libvirtIntegration model and management layer comparison
Storage Backend SelectionChoosing between Local, NFS, LVM, ZFS, and Ceph
Networking ArchitectureOverlay vs. flat networking decisions

Features​

Detailed documentation for each major feature area.

VM Lifecycle​

DocumentDescription
VM CreationCreateVMRequest fields, validation rules, defaults
VM Start OptionsVMStartOptions reference -- KVM, TPM, Secure Boot, networking
VM StatesState machine: Stopped, Starting, Running, Paused, Stopping, Failed
VM CloningFull and linked clones with CoW support
VM TemplatesCreate, manage, and deploy from templates
VM ProfilesInstance types and resource presets
VM ImportImport from VMDK, VDI, VHD formats
OVA/OVF ExportExport VMs to OVA/OVF format for portability
Declarative SpecsYAML-based VM definitions with fabricctl apply
VM CheckpointsCreate and restore in-memory checkpoints
VM ForkingFork a running VM for testing

Container Workloads​

DocumentDescription
Container GroupsKubernetes-style Pod groups backed by FluxVM Secure Containers -- tenant scoping, image pull secrets, health probes, NetworkPolicy, quotas/billing, backup/restore

Storage​

DocumentDescription
Storage OverviewStorage architecture and backend selection
Local StorageFile-based qcow2/raw storage pools
NFS StorageNFS Storage Guide
LVM StorageLogical Volume Manager pools and thin provisioning
ZFS StorageZFS pools, datasets, and replication
Ceph/RBD StorageCeph cluster integration and RBD image management
Volume ManagementCRUD, attach/detach, resize, and clone volumes
SnapshotsCreate, revert, delete, and tree-view snapshots
Distributed StorageCross-node storage pools, migrations, and policies
Datastore ClustersStorage DRS and placement recommendations
iSCSI StorageiSCSI target discovery, login, and LUN management
Cloud ImagesBuilt-in catalog download (Ubuntu, Fedora, Debian, Alma)
ISO ManagementDownload, list, and manage ISO images
Online Disk ResizeGrow VM disks without downtime

Networking​

DocumentDescription
Networking OverviewNetwork architecture, SDN stack, and VM edge dataplane
VM edge dataplane (Network Fabric schema v4)Fabric proxy of FluxVM TC/eBPF — API, Web, CLI, lab UX
Service Fabric v6 (Maglev VIP LB)FluxVM Maglev/NAT/DSR/EDT/flows/policy + Fabric leases, HA, FRR/BIRD
AI Workloads (Beta)GPU VMs, Janus lab upstream, PCI MIG flag, admit webhook, fabric-inference JWT, revisioned rollouts, gateway limits, Maglev, Terraform, operator CRDs
User: VM DataplaneConsole walkthrough for Status / Policy / Effective / Stats / Flows
User: Edge DataplaneCluster groups / CNP / Maglev Services / health / observe console
Tutorial 09: Edge DataplaneEnd-to-end lab (API + CLI + UX)
Edge dataplane seriesShort labs: groups, CNP, FQDN, UX
Networking (netlink)Bridges, VLANs, bonds, taps, macvtaps, VXLANs, SR-IOV
Network PoliciesCilium-style label-based ingress/egress rules
VM FirewallPer-VM firewall profiles and zones via nftables
Service MeshVirtual IP load balancing (round-robin, least-conn, IP-hash)
Traffic ShapingQoS: guaranteed rate, max rate, burst, priority-based bandwidth
DNS PoliciesZone management, upstream servers, domain blocking
VPN MeshWireGuard tunnels: point-to-point, hub-spoke, full-mesh
NAT GatewayMasquerade, SNAT, DNAT, hairpin NAT
Packet MirrorTraffic capture and debugging
Network MonitorPer-VM bandwidth tracking with threshold alerts
Floating IPsVirtual IP allocation and VM assignment
DHCP ServersPer-bridge dnsmasq-managed DHCP servers
DHCP ServerBuilt-in DHCP server on bridge interfaces
Port ForwardingNAT-based port forwarding rules

Security and Identity​

DocumentDescription
Security OverviewSecurity architecture and audit history
AuthenticationPAM + JWT authentication flow
RBACAdmin, User, Viewer roles and endpoint permissions
API KeysService-to-service authentication tokens
OIDC / External AuthLDAP and OIDC/OAuth2 SSO (PKCE, JWKS-verified id_token)
SCIM ProvisioningSCIM 2.0 lifecycle provisioning and group-to-role sync for Entra ID / Okta
OpenStack CompatibilityExperimental Keystone/Nova/Glance/Neutron/Cinder façade on the same daemon port
Audit LoggingStructured audit logs with JSON/CSV export
EncryptionVM disk encryption with key management providers
TLS/HTTPSCertificate management and self-signed TLS generation
Multi-TenancyProject isolation with member roles and quotas
2FA/MFA AuthenticationTOTP-based two-factor authentication for user accounts
Secrets ManagementSecure storage and retrieval of credentials and sensitive data
Compliance ScanningAutomated compliance profile scanning and reporting
JWT RevocationPer-token revocation via JTI blocklist
Credential Managementsystemd credentials, SSH keys, and cloud-init secrets

High Availability​

DocumentDescription
DRSDistributed Resource Scheduling and placement
Affinity RulesVM-to-VM and VM-to-host affinity/anti-affinity
Host Maintenance EvacuationPreflight-checked workload evacuation before a host enters maintenance
Fabric DoctorProduction host preflight checks and safe support bundles (tools/fabric-doctor)
Fault ToleranceAutomatic failover, fencing, and recovery
Live MigrationDisk-copy: iterative rsync pre-copy + cutover; native FluxVM transport = preview (receivers)
Site RecoveryFailover/reprotect workflows for disaster recovery
Resource OvercommitCPU/memory/storage overcommit policies
Split-Brain ProtectionQuorum-based fencing to prevent split-brain in clusters
Auto-ScalingMetric-based scaling policies and events

Monitoring and Automation​

DocumentDescription
Prometheus Metrics/metrics endpoint and metric catalog
Analytics DashboardHistorical performance data and insights
NotificationsEmail, Slack, Webhook, Microsoft Teams channels
SchedulesOnce, daily, weekly VM operations scheduling
Backup AutomationRetention policies, incremental backups, systemd timers
Resource QuotasPer-user and per-project resource limits
OptimizationResource optimization recommendations
Log AggregationCentralized VM log collection, search, and streaming
Health ChecksDeep health check: API, disk, DB, credentials, KVM

Console Access​

DocumentDescription
WebSocket ConsoleBrowser-based terminal via xterm.js
VNC ConsoleGraphical console via noVNC proxy
SPICE DisplaySPICE protocol support for high-performance remote display
Console ModesInteractive, read-only, native, GUI

Advanced Virtualization​

DocumentDescription
GPU PassthroughGeneric PCI/VFIO passthrough for NVIDIA and AMD GPUs (no vGPU/Intel GVT-g)
CPU/NUMA OptimizationCPU pinning, NUMA topology, hugepages
KSM Memory DedupKernel Same-page Merging configuration
Nested VirtualizationRunning VMs inside VMs
HotplugCPU, memory, disk, and NIC hot-add/remove
FirmwareUEFI, Secure Boot, NVRAM management
TPMvTPM support via swtpm
Direct Kernel BootBoot from kernel + initrd without bootloader
Bind MountsHost-to-VM filesystem sharing
USB PassthroughHost USB device passthrough to VMs
User NamespacesPrivate user mapping for isolation

Architecture​

DocumentDescription
Architecture OverviewSystem architecture and component diagram
Crate Structure53 backend crates and their responsibilities
Data ModelVM, VMStartOptions, VMMetrics, VMPressure
Driver ModelVMDriver and ResourceStatsDriver traits
State StoreSQLite-based persistent state management
Event SystemBroadcast channels and SSE event streaming
Background TasksReconciliation loops and schedulers
Plugin SystemPlugin registry and extension points

Reference​

API Reference​

DocumentDescription
API OverviewAuthentication, pagination, error format
VM EndpointsCRUD, lifecycle, metrics, cloud-init
Storage EndpointsPool and volume management
Network EndpointsBridges/VLANs/bonds via netlink, policies, firewall, mesh
Security EndpointsAuth, audit, encryption, tenants
System EndpointsCPU topology, NUMA, memory, firmware
Enterprise EndpointsDatacenters, clusters, hosts, DRS
Machine EndpointsVM driver: FluxVM (no systemd dependency)
Monitoring EndpointsAnalytics, events, notifications, schedules
Backup EndpointsBackup CRUD, policies, restore
Billing EndpointsUsage tracking, pricing, and invoicing
WebSocket EndpointsConsole, VNC, event streaming

CLI Reference​

CommandDescription
fabricctl / fabricctl --helpCilium-style grouped help with emoji section markers (Basic, Dataplane, Networking, Meta, …)
fabricctl listList VMs (paginated {items, total, …} from GET /api/vms); set FABRIC_URL + FABRIC_TOKEN or ZYVOR_FABRIC_* for HTTPS labs
fabricctl createCreate a new VM
fabricctl startStart a stopped VM
fabricctl stopStop a running VM
fabricctl restartRestart a VM
fabricctl deleteDelete a VM
fabricctl applyApply declarative YAML specification
fabricctl policyManage network policies
fabricctl dataplaneVM edge dataplane (policy, flows, hubble, CNP, …)
fabricctl statusFabric API + dataplane health checklist
fabricctl configShow effective server/token/color settings
fabricctl completionGenerate bash/zsh/fish completion scripts
fabricctl cephCeph storage management
fabricctl metricsGet VM metrics

Global flags: -o table|json|yaml, --color auto|always|never, --server, --token.

VM console/VNC access is Web/REST-only (GET /ws/console/:name, /ws/vnc/:name) — there is no fabricctl console command.

zyvor-fabricd-ctl Reference​

CommandDescription
zyvor-fabricd-ctl deployFull deployment (deps + build + install + start)
zyvor-fabricd-ctl depsInstall system dependencies
zyvor-fabricd-ctl buildBuild from source
zyvor-fabricd-ctl installInstall binaries and systemd units
zyvor-fabricd-ctl startStart the zyvor-fabricd service
zyvor-fabricd-ctl stopStop the zyvor-fabricd service
zyvor-fabricd-ctl restartRestart the service
zyvor-fabricd-ctl statusShow service status
zyvor-fabricd-ctl logsFollow service logs
zyvor-fabricd-ctl verifyPost-install smoke test
zyvor-fabricd-ctl healthDeep health check
zyvor-fabricd-ctl passwordRead the admin password
zyvor-fabricd-ctl doctorSystem readiness check
zyvor-fabricd-ctl tlsGenerate self-signed TLS certificate
zyvor-fabricd-ctl upgradeGit pull + reinstall
zyvor-fabricd-ctl uninstallRemove everything
zyvor-fabricd-ctl billingView billing and usage reports
zyvor-fabricd-ctl backup nowTrigger immediate backup
zyvor-fabricd-ctl backup enableEnable daily backup timer
zyvor-fabricd-ctl backup statusShow backup timer and storage info

Rust SDK​

ItemDescription
zyvor-fabric-sdkTyped Rust SDK for the Zyvor Fabric API with async client
AuthenticationLogin, token refresh, and 2FA helpers
VM OperationsCreate, start, stop, delete, clone, and snapshot VMs
Storage / NetworkingPool, volume, bridge, VLAN, and firewall management
StreamingWebSocket console attach and SSE event subscriptions

Deployment​

DocumentDescription
KubernetesRun fabricd + FluxVM as privileged DaemonSets; Helm; lab ./scripts/deploy k8s
Docker / PodmanLocal eval with compose (hostNetwork + KVM)
Single ServerOne-node deployment for development and small teams
Multi-Node ClusterHA deployment with shared storage and etcd
Kubernetes OperatorVMs as CRDs with the zyvor-fabricd operator (operator/)
Terraform ProviderDeclarative provisioning with plan/apply
Edge DeploymentLightweight single-node deployment for edge locations
Air-Gapped InstallOffline installation without internet access

Development​

DocumentDescription
Development SetupRust toolchain, IDE, and local development
Build and Testcargo check, cargo test, CI pipeline
Crate Map53 crates and their dependencies
Adding an API EndpointStep-by-step guide for new endpoints
Adding a Storage BackendDriver trait implementation guide
Adding a Network FeatureIntegration with the netlink-based networking crate
Code StyleFormatting, naming, error handling conventions
Security GuidelinesInput validation, path traversal prevention, audit

Quick Reference​

See also the standalone quick-reference docs: FAQ · Glossary · Quick reference cheatsheet.

API Endpoint Categories​

The REST API is organized into the following endpoint groups:

CategoryPrefixEndpointsDescription
Authentication/api/auth/6Login, 2FA/TOTP setup, and session management
SCIM Identity/api/identity/scim/, /scim/v2/21Provisioning profiles/tokens (JWT) plus SCIM Users/Groups (bearer token)
OpenStack Compatibility/identity, /compute, /image, /network, /volume—Experimental OpenStack wire protocol (catalog from public_url)
VM Lifecycle/api/vms/12CRUD, start, stop, restart, pause, resume, clone
VM Advanced/api/vms/{name}/20+Hotplug, checkpoints, fork, disk resize, firmware
Snapshots/api/vms/{name}/snapshots/5Create, list, get, delete, revert
Cloud-Init/api/vms/{name}/cloud-init1Configure cloud-init for a VM
Storage Pools/api/storage/pools/14Pool CRUD, health, stats, refresh
Volumes/api/storage/pools/{name}/volumes/6Volume CRUD, resize, attach, detach
Distributed Storage/api/distributed-storage/18Cross-node pools, migrations, policies
Networking/api/networkd/35+Bridges, VLANs, bonds, taps, VXLANs, SR-IOV (netlink-based)
Network Policies/api/network-policies/5Cilium-style ingress/egress rules
VM Firewall/api/vm-firewall/8+Per-VM firewall profiles and zones
Service Mesh/api/service-mesh/10+Virtual IP and load balancing
Traffic Shaping/api/traffic-shaping/8+QoS and bandwidth management
DNS Policies/api/dns-policies/6+Zone management and blocking
VPN Mesh/api/vpn-mesh/6+WireGuard tunnel management
NAT Gateway/api/nat-gateway/6+Masquerade, SNAT, DNAT
Packet Mirror/api/packet-mirror/4+Traffic capture
Net Monitor/api/net-monitor/4+Bandwidth tracking and alerts
Floating IPs/api/floating-ips/4Virtual IP allocation
DHCP/api/dhcp-servers/2Per-bridge dnsmasq-managed DHCP servers
DNS/api/dns/4DNS configuration
Encryption/api/encryption/11Key providers, policies, VM encryption
Backups/api/backups/11Backup CRUD, policies, restore, stats
Schedules/api/schedules/9Timed VM operations
Quotas/api/quotas/8Resource quotas and usage
Notifications/api/notifications/11Multi-channel alerting
Audit/api/audit/4Audit logs and export
Analytics/api/analytics/6Performance data and insights
Templates/api/templates/5VM templates and deployment
Profiles/api/profiles/3Instance type presets
Images/api/images/10Image build, cloud download, ISO, import
Migrations/api/migrations/3Live VM migration
Events/api/events/2Event list and SSE stream
System/api/system/12CPU, NUMA, memory, hugepages, optimization
Firmware/api/vms/{name}/firmware/5UEFI, Secure Boot, NVRAM
Datacenters/api/datacenters/5Datacenter management
Clusters/api/clusters/5Cluster management and health
Hosts/api/hosts/8Host registration and maintenance
DRS/api/drs/9Scheduling, placement, affinity rules
Resource Pools/api/resource-pools/7Resource pool management
Zones/api/zones/3Availability zones
Spot Instances/api/spot-instances/3Spot VM management
Tenants/api/tenants/variesMulti-tenancy and projects
Settings/api/settings2Global settings
Plugins/api/plugins1Plugin registry
OVA Export/api/vms/{name}/export/2OVA/OVF export
Secrets/api/secrets/5Secrets and credential management
Compliance/api/compliance/6Compliance profile scanning and results
Billing/api/billing/6Usage tracking, pricing, and invoicing
Logs/api/logs/4Centralized log aggregation and search
iSCSI/api/iscsi/5iSCSI target discovery and session management
USB/api/usb/4USB device listing and passthrough
SPICE/api/vms/{name}/spice/2SPICE display connection
Declarative/api/vms/apply2YAML spec apply and export
Auto-Scale/api/autoscale/4Scaling policies and events
WebSocket/api/ws/3Console, VNC, events

Default Ports and Paths​

ItemDefault
API listen address127.0.0.1:9095
Config file/etc/zyvor-fabricd/zyvor-fabricd.toml
State directory/var/lib/zyvor-fabricd/
Image directory/var/lib/zyvor-fabricd/images/
Auth database/var/lib/zyvor-fabricd/auth.db
Cloud-init directory/var/lib/zyvor-fabricd/cloud-init/
Storage pools/var/lib/zyvor-fabricd/storage/
JWT secret file/var/lib/zyvor-fabricd/.jwt_secret
Admin password file/var/lib/zyvor-fabricd/.admin_password
networkd config dir/etc/systemd/network/
networkd file prefix50-Zyvor Fabric-
Network bridgebr0

VM Resource Limits​

ResourceMinimumMaximumDefault
CPUs1256--
Memory128 MB1,048,576 MB (1 TB)--
Disk1 GB65,536 GB (64 TB)20 GB

VM States​

StateDescription
stoppedVM is not running
startingVM is in the process of booting
runningVM is running and accessible
pausedVM is suspended in memory
stoppingVM is in the process of shutting down
failedVM failed to start or encountered an error
unknownVM state could not be determined

RBAC Roles​

RoleReadWriteAdmin
ViewerYesNoNo
UserYesYesNo
AdminYesYesYes

Environment Variables​

VariableDescription
ZYVOR_FABRICD_LISTENOverride daemon.listen (e.g. 0.0.0.0:9095)
ZYVOR_FABRICD_PUBLIC_URLExternal base URL for OpenStack catalog / clients
ZYVOR_FABRICD_CONFIGOverride config file path
ZYVOR_FABRICD_LOG_LEVELOverride log level
ZYVOR_FABRICD_JWT_SECRETOverride JWT signing secret
ZYVOR_FABRICD_ADMIN_PASSWORDOverride default admin password
ZYVOR_FABRICD_BACKUP_DIROverride backup directory
ZYVOR_FABRICD_BACKUP_RETAINOverride backup retention count
ZYVOR_FABRICD_BACKUP_TYPEOverride backup type

AI Workloads (Beta)​

OpenAI-compatible inference on dedicated NVIDIA GPU VMs: ModelArtifact / InferenceProfile / InferenceDeployment / InferenceEndpoint, revisioned rollouts, Maglev weighting, gateway rate limits, an API-key (or fabric-inference JWT) OpenAI gateway at /api/ai/openai/{endpoint}, and an optional Janus stand-in when the host has no NVIDIA GPU. Console: /app/ai. Single-cluster Beta (not GA). Multi-site HA store stays Preview.

DocumentDescription
ai-workloads.mdFull reference: REST, CLI, Janus, PCI MIG, admit, Raft, runtimes
Tutorial 15Operator how-to: model → chat → MIG
scripts/bake-ai-vllm-image.shBake CUDA + vLLM qcow2
scripts/smoke-ai-janus-lab.shLab smoke: health, chat, MIG, admit
terraform-provider/examples/ai-workloadsTerraform model/profile/deployment/endpoint
operator/examples/ai-inference-deployment.yamlModelArtifact + InferenceDeployment CRs
operator chart admissionWebhookOpt-in ValidatingWebhook for InferenceDeployment
Agent Runtime ↔ Fabrickind: fabric credentials for on-prem models

Agent Runtime​

Standalone component: durable agent sessions in a FluxVM sandbox, or on a GitHub runner through a FluxVM stand-in. A session runs a JavaScript worker or a claude, codex, or gemini CLI. Provider keys stay on the host egress broker. The crate also accepts cron schedules, signed webhooks, bounded loops, operator approvals, agent-to-agent delegation, and a small MCP server. Lives in agent-runtime/ (Rust daemon), sdk/agent-runtime/ (SDK + fabric-agent CLI), and examples/agent-runtime/ — outside the backend/ Cargo workspace.

DocumentDescription
agent-runtime/README.mdDeploy/run, harness, schedules, MCP, HTTP API, warm pools, session CI
Tutorial 11Build a Node.js FluxVM template and drive a session
Tutorial 13Build a bundle and deploy it from the web console
Tutorial 14Use cases: ops, coding, research, cron, webhook, loop, approval, handoff, IDE chat, fan-out
examples/agent-runtime/README.mdOps health check, hello-go, warm pool, and fan-out

Integrations​

Product Positioning​


Client Presentations​

DocumentDescription
Product OverviewComprehensive product overview with feature matrix
Product Overview (PDF)Printable product overview
Security Audit ReportFull security audit report
Security Audit Report (PDF)Printable security audit report

This index is maintained alongside the codebase. For the latest information, refer to the source code and inline documentation.