Documentation · Platform Architecture

Architecture & Administration Guide

This guide explains how VirtStack is built and how to operate it day to day. It assumes familiarity with SLES, libvirt and KVM.

Operating model: Day 0, Day 1, Day 2

PhaseWhoToolingTasks
Day 0 · FoundationPlatform engineersStandard SUSE tooling (YaST, zypper, crmsh)Servers, SLES 15 SP7 + KVM, networks/bonds/bridges, SAN/NAS, Pacemaker/Corosync/SBD, hardening
Day 1 · OnboardingPlatform engineers, VirtStack-assistedVirtStackEnroll hosts, discover hardware & NUMA, register pools & networks, build golden templates, set placement defaults, adopt existing VMs
Day 2 · OperationsL1–L3 operationsVirtStackLifecycle and console, snapshots, clones, placement, HA visibility, maintenance mode, metrics, audit

VirtStack does not build the Pacemaker cluster (use SUSE HA tooling such as crmsh); it discovers and visualises it. It does not replace Hawk2, which remains the SUSE HA cluster-resource UI.

Architecture overview & 4 design principles

1. Outbound-only from hosts

The agent initiates connection. Control plane cannot reach a host that has not dialled in.

2. No central host credentials

No root passwords or SSH keys stored centrally. Each agent authenticates with its own certificate.

3. Local execution

Operations run through libvirt's local UNIX socket on host, not over remote virsh or SSH.

4. libvirt source of truth

VMs are standard libvirt domains. Existing VMs are discovered; VirtStack can be cleanly uninstalled.

ComponentRuns onResponsibility
Web UIControl planeBrowser console, dashboards, noVNC client
APIControl planeAuthenticated operations, validation, audit logging
GatewayControl planeTerminates agent mTLS tunnels; multiplexes control, events and console streams
Placement engineControl planeFilter + score hosts; NUMA pinning recommendations; decision log
Audit logControl planeAppend-only record of administrative actions
AgentEach hypervisorEnrolls, maintains tunnel, executes libvirt RPC locally, streams events and metrics
libvirt / QEMU / KVMEach hypervisorSUSE-packaged virtualization stack; VirtStack does not replace it

Host administration & agent commands

Agent Systemd Commands

Agent service management on SLES
sudo systemctl status virtstack-agent
sudo journalctl -u virtstack-agent --since "1 hour ago"
sudo systemctl restart virtstack-agent   # safe: running VMs are not affected

Standalone Host Patch Procedure

zypper patch on SLES
# after shutting down or relocating VMs
sudo zypper patch
sudo zypper needs-rebooting   # reboot if it reports that one is required

Storage & Online Volume Expansion

Discovers Directory, NFS, and LVM pools. Online volume expansion presents new size to guest immediately.

Inside Linux Guest Partition & Filesystem Expansion
sudo growpart /dev/vda 2
sudo xfs_growfs /            # XFS
# or: sudo resize2fs /dev/vda2   # ext4

Current limits

AreaTodayRoadmap
MigrationWizard with capacity & compatibility validationLive migration; storage copy without shared storage
ScaleSingle gatewayPooled gateways, 50+ hypervisors
Access controlAdministrator accounts; restrict console via network VPNRBAC, SSO, MFA
Host maintenanceMaintenance mode + manual moves via wizardOne-click evacuation
VMware importConvert with virt-v2v outside VirtStackNot on committed roadmap

Ready to inspect security & compliance?

Ready for SLES 15 SP7 KVM?

60-day evaluation • 4 sockets included