Skip to main content

Zyvor Fabric Crate Map

This document catalogs the crates in the Zyvor Fabric workspace, organized by domain. Each entry includes the crate name, workspace path, and a brief description of its purpose.


Table of Contents​

  1. Core
  2. Drivers
  3. Networking
  4. Storage
  5. System Internals
  6. Management
  7. Infrastructure
  8. Utilities
  9. CLI and UI
  10. Dependency Summary

Core​

These crates form the foundation of the Zyvor Fabric platform.

CratePathDescription
zyvor-fabricdbackend/zyvor-fabricdMain daemon binary. Axum HTTP server, 780+ REST endpoints, WebSocket console, SSE events, background task orchestrator, plugin system.
vm-modelbackend/vm-modelCore data structures: VM, VMState, CreateVMRequest, VMStartOptions, VMMetrics. Shared across all crates.
state-storebackend/state-storeFile-based persistent storage. Atomic JSON writes, in-memory VM cache, paginated queries, path traversal protection.
securitybackend/securityAuthentication and authorization. JWT token management, PAM integration, RBAC (Admin/User/Viewer), user database (SQLite), audit logging, Axum extractors.

Drivers​

Zyvor Fabric's VM lifecycle is entirely owned by FluxVM, a disposable-VM engine with no systemd dependency of its own, reached over its REST API. driver-core defines the trait boundary (VmDriver) between the daemon and that backend; there is no other backend to select — the systemd-machined/systemd-vmspawn driver (machinectl-driver/machined-dbus) that used to fill this role has been deleted.

CratePathDescription
zyvor-fabric-driver-corebackend/crates/driver-coreTrait definitions the driver implements: VMDriver (lifecycle), ResourceControlDriver/ResourceStatsDriver (cgroup quotas, freeze/thaw, metrics, PSI pressure), LogDriver (log streaming), ImageDriver (image registry CRUD), ShellDriver (exec/copy), ConsoleDriver (interactive console), CapabilityProvider. Blanket-impl'd as VmDriver.
zyvor-fabric-vm-driverbackend/zyvor-fabric-vm-driverBuilds VM disk images via mkosi (an offline OS-image-building tool) -- unrelated to VM lifecycle, which is entirely FluxVM's job.
zyvor-fabric-fluxvm-clientbackend/crates/fluxvm-clientREST client for FluxVM's API -- hand-maintained DTO mirror, since the integration is out-of-process REST rather than a Cargo dependency on FluxVM's own crates.
zyvor-fabric-fluxvm-driverbackend/crates/fluxvm-driverVmDriver implementation backed by FluxVM. A few ImageDriver operations (tar-format images) intentionally error rather than fake an equivalent that can't exist -- a tar rootfs isn't a bootable disk image for a real hardware VM.

Networking​

Twelve crates provide a full-featured software-defined networking stack.

CratePathDescription
networkingbackend/networkingBase networking utilities. Bridge, VLAN, TAP, bond, and VXLAN setup via direct netlink (rtnetlink) calls -- no config-file/reload step, no systemd-networkd dependency.
network-policybackend/network-policyL3/L4 network access control. Policy engine for identity-based traffic rules. Integrates with nftables for enforcement.
service-meshbackend/service-meshService discovery and load balancing. Service registration, backend health checking, traffic routing.
service-lbbackend/service-lbFabric-side orchestration for FluxVM Service Fabric v6+ -- service intent, node selection, rollout/rollback, multi-site site_id/route_domain fencing. Never touches bpffs/tc/bpftool directly; FluxVM owns every TC/XDP program and BPF map.
traffic-shapingbackend/traffic-shapingQuality of Service (QoS) management. Bandwidth limits, priority queuing via Linux tc (traffic control).
dns-policybackend/dns-policyDNS zone and record management. Per-VM DNS policies, zone delegation, integration with systemd-resolved.
vm-firewallbackend/vm-firewallPer-VM firewall management. Firewall profiles and zones. Rules enforcement via nftables.
vpn-meshbackend/vpn-meshVPN mesh networking. WireGuard tunnel creation and management, overlay network topology.
packet-mirrorbackend/packet-mirrorTraffic mirroring. Mirror session management for network debugging and analysis.
nat-gatewaybackend/nat-gatewayNAT gateway management. SNAT/DNAT rules, NAT pools, gateway lifecycle.
net-monitorbackend/net-monitorNetwork monitoring. Per-VM bandwidth metrics collection, alerting policies, threshold-based notifications.
zyvor-fabric-dnsmasq-managerbackend/crates/dnsmasq-managerPer-bridge DHCP server: spawns and supervises a dnsmasq process directly, replacing systemd-networkd's built-in [DHCPServer].

Storage​

CratePathDescription
zyvor-fabric-storagebackend/crates/storageStorage pool and volume management. Supports Local, NFS, LVM, LVM-Thin, ZFS, and Ceph backends. Volume attach/detach, online resize.
distributed-storagebackend/distributed-storageDistributed storage orchestration. Datastore clusters, storage migration, storage policies, SDRS recommendations, compliance checking.

System Internals​

CratePathDescription
zyvor-fabric-systembackend/crates/systemSystem resource management. CPU topology, NUMA placement, memory balloon, hugepages, KSM deduplication, nested virtualization.
zyvor-fabric-vmbackend/crates/vmVM-level utilities. Checkpoint/restore, VM forking, hotplug (CPU, memory, disk, NIC), firmware management (UEFI, Secure Boot, TPM).
zyvor-fabric-lock-managerbackend/crates/lock-managerDistributed lock management. Per-resource advisory locks with configurable TTL and automatic renewal.
zyvor-fabric-cgroupbackend/crates/cgroupCgroup v2 integration. Resource accounting, CPU/memory/IO limits for VMs via the cgroup hierarchy.

Management​

Enterprise management features for large-scale VM deployments.

CratePathDescription
lifecycle-managerbackend/lifecycle-managerHost lifecycle management. Baseline definitions, compliance scanning, remediation tasks, rolling updates with pause/advance.
certificate-managerbackend/certificate-managerPKI and certificate management. CA creation, certificate issuance/renewal/revocation, automated rotation, security baselines, hardware attestation.
resource-poolsbackend/resource-poolsResource pool management. CPU/memory/storage reservation, admission control, VM assignment, pool-level quotas.
encryptionbackend/encryptionVM disk encryption. Key management provider integration, encryption policies, per-VM encrypt/decrypt, key rotation.
site-recoverybackend/site-recoveryDisaster recovery orchestration. Recovery plans, planned migration, disaster failover, test failover, reprotection workflows.
replicationbackend/replicationVM replication. Multi-site replication configuration, sync scheduling, RPO monitoring, recovery instance management.
migrationbackend/migrationVM migration. Live migration between hosts, progress tracking, migration cancellation.
predictive-drsbackend/predictive-drsPredictive Distributed Resource Scheduler. Resource demand forecasting, proactive placement, trend analysis.
secrets-managerbackend/secrets-managerSecrets and credential storage. Encrypted at-rest secret store with CRUD API, access policies, and automatic rotation.
compliancebackend/complianceCompliance profile scanning. Built-in profiles (CIS, STIG, PCI-DSS), per-VM scanning, finding severity, remediation guidance.
billingbackend/billingUsage tracking, pricing, and invoicing. Per-VM metering, configurable pricing tiers, invoice generation, chargeback reports.
enterprise-identitybackend/enterprise-identitySCIM 2.0 models, provisioning tokens, patch/filter engine, and group-to-role resolution for Entra ID / Okta.
openstack-compatbackend/openstack-compatOpenStack wire-protocol façade (Keystone/Nova/Glance/Neutron/Cinder) mounted on zyvor-fabricd.
host-lifecyclebackend/host-lifecycleHost maintenance evacuation planner and async job manager (preflight, capacity-aware placement).

Infrastructure​

CratePathDescription
datacenterbackend/datacenterDatacenter hierarchy management. Datacenters, clusters, hosts. Host registration, heartbeat, maintenance mode, health monitoring, auto-discovery.
host-agentbackend/host-agentAgent for remote host management. Runs on cluster member hosts, reports resource availability, executes controller commands.
fault-tolerancebackend/fault-toleranceHigh availability. Continuous VM replication, automatic failover detection, test failover, replication suspend/resume, FT metrics.
content-librarybackend/content-libraryCentralized content management. Image and template libraries, cross-site synchronization, customization specs, host profiles, compliance.
tpm-supportbackend/tpm-supportTPM 2.0 integration. Virtual TPM device management for Secure Boot and measured boot chains.
k8s-pod-clientbackend/crates/k8s-pod-clientOutbound client for placing Container Group Pods on a customer-owned Kubernetes cluster. Thin CRUD wrapper (kube::Api<Pod>) only -- no controller/watch loop, which belongs to zyvor-fabricd-operator.

Utilities​

CratePathDescription
cloud-initbackend/cloud-initCloud-init configuration generation. User-data, meta-data, network-config for NoCloud datasource. SSH key injection, package installation.
prometheus-exporterbackend/prometheus-exporterPrometheus metrics. Exposes zyvor_fabricd_vms_total, zyvor_fabricd_vms_running, zyvor_fabricd_vm_starts_total, etc. via /metrics endpoint.
vnc-proxybackend/vnc-proxyWebSocket-to-VNC proxy. Bridges browser-based noVNC client to QEMU VNC server for graphical VM console.
ova-toolsbackend/ova-toolsOVA/OVF export and import. Builds OVA archives from VM disk images and metadata, parses OVF descriptors for import.
api-errorbackend/crates/api-errorShared HTTP/API error formatting -- consistent error labels and messages across the daemon and its web/CLI clients.

CLI and UI​

CratePathDescription
fabricctlbackend/fabricctlCommand-line client. Talks to Zyvor Fabric REST API. VM lifecycle commands, image management, status queries.
zyvor-fabric-sdkbackend/zyvor-fabric-sdkTyped Rust SDK for the Zyvor Fabric API. Async client with builder pattern, authentication helpers, VM lifecycle, storage, networking, and streaming support.

Web UI (not a Rust crate)​

ComponentPathDescription
zyvor-fabric-webweb/React 19 + TypeScript web application. Vite build, Tailwind CSS, React Router, Recharts dashboards, xterm.js console, noVNC graphical console.

Dependency Summary​

External Crate Dependencies​

DependencyVersionUsed ByPurpose
tokio1.44All async cratesAsync runtime
axum0.8Zyvor FabricHTTP framework
serde / serde_json1.0All cratesSerialization
anyhow / thiserror1.0/2.0All cratesError handling
tracing0.1All cratesStructured logging
tower-http0.6Zyvor FabricCORS, file serving, tracing
reqwest0.12Zyvor FabricHTTP client for webhooks
lettre0.11Zyvor FabricSMTP email notifications
rusqlite-securitySQLite user database
jsonwebtoken-securityJWT encode/decode
pam-securityPAM authentication
prometheus-prometheus-exporterMetrics registry
uuid1.16All cratesUUID v4/v5 generation
chrono0.4All cratesDate/time handling
clap4.5fabricctlCLI argument parsing
futures0.3Async cratesStream/sink utilities
rand0.9security, coreRandom number generation
tar / flate20.4/1.1content-libraryArchive handling
regex1.11validationInput validation patterns
toml0.8Zyvor FabricConfiguration file parsing
tokio-util0.7Zyvor FabricCancellationToken for shutdown

Internal Dependency Flow​

Zyvor Fabric (main binary)
|-- vm-model
|-- state-store --> vm-model
|-- security
|-- api-error
|-- zyvor-fabric-vm-driver
|-- zyvor-fabric-driver-core --> vm-model
|-- zyvor-fabric-fluxvm-client
|-- zyvor-fabric-fluxvm-driver --> zyvor-fabric-driver-core, zyvor-fabric-fluxvm-client
|-- zyvor-fabric-storage
|-- zyvor-fabric-system
|-- zyvor-fabric-vm
|-- zyvor-fabric-lock-manager
|-- zyvor-fabric-cgroup
|-- networking
|-- zyvor-fabric-dnsmasq-manager
|-- network-policy
|-- service-mesh
|-- traffic-shaping
|-- dns-policy
|-- vm-firewall
|-- vpn-mesh
|-- packet-mirror
|-- nat-gateway
|-- net-monitor
|-- service-lb
|-- cloud-init
|-- prometheus-exporter
|-- vnc-proxy
|-- tpm-support
|-- datacenter
|-- resource-pools
|-- encryption
|-- predictive-drs
|-- distributed-storage
|-- fault-tolerance
|-- replication
|-- migration
|-- site-recovery
|-- content-library
|-- lifecycle-manager
|-- certificate-manager
|-- ova-tools --> vm-model
|-- secrets-manager
|-- compliance --> vm-model, state-store
|-- billing --> vm-model, state-store
|-- enterprise-identity
|-- openstack-compat
|-- host-lifecycle
|-- k8s-pod-client