Skip to main content

Compatibility matrix

Issue #17 — Fabric × FluxVM × GuestKit × Kubernetes versions.

Status values:

  • CI — exercised on GitHub Actions (ci.yml, fabric-e2e.yml, operator.yml, agent-runtime.yml). lab-deploy.yml rebuilds the lab host on push to main.
  • Lab — documented lab path (docs/DOCKER.md, docs/KUBERNETES.md)
  • Unverified — combination exists in the wild but is not gated here

Control plane​

FabricWorkspaceNotes
0.2.1 / main48+1 (backup now a workspace member)JWT tenant scoping, /readyz, OpenStack façade experimental

VM engine​

FluxVMFabric driverStatus
FluxVM main / /readyz presentcrates/fluxvm-driver + driver.fluxvm_urlLab + e2e when FLUXVM_URL is set
FluxVM with auth tokendriver.fluxvm_tokenLab
No FluxVMdaemon serves API/UI onlyCI (API audit, unit tests)

Fabric does not execute VMs itself. Combinations without a reachable FluxVM cannot create/start/stop guests.

Disk tooling​

GuestKitUsed forStatus
GuestKit mainOffline image customize (NBD)Lab — host nbd module required
Absentqcow2/raw as-isCI

Kubernetes​

KubernetesFabric deployOperatorStatus
kind (CI)not requiredoperator/ reconcile e2e (mocked API)CI
k3s / kubeadm 1.29–1.33Helm charts/zyvor-fabric hostNetwork DaemonSets, NodePort 30095Helm operator/charts/zyvor-fabricd-operatorLab
OpenShift / managed EKS/GKE/AKSnot packagedUnverifiedUnverified

Auth / identity​

ProviderStatus
Local JWT + bcrypt usersCI
OIDC PKCE + JWKSCI unit + documented Keycloak/Entra/Okta
SCIM 2.0CI crate tests
OpenStack Keystone façadeExperimental — password not bound to Fabric identity

Storage backends (control-plane API)​

BackendCreate/attach in unit testsLive I/O
Local filesystemyes (backup crate)CI
NFS / LVM / ZFS / CephAPI + docsLab

How to extend this matrix​

Add a row only after a recorded run:

./scripts/chaos-qualify.sh --report docs/proven-infra/runs/
./benchmarks/harness.py --base-url "$FABRIC_URL" --out benchmarks/baselines/$(date +%F).json