Designed so the server holds zero root secrets
Most virtualization managers become the single most valuable target on the network: one server holding the root credentials to every hypervisor. VirtStack is designed so that server holds none.
Security model
No root passwords, SSH private keys or libvirt TCP credentials stored on the control plane. Each agent authenticates with its own certificate issued at enrollment. Revoking a host revokes only that host's certificate.
Agents open an outbound TLS connection; no inbound listener is required on hosts. Works behind NAT and egress-only firewalls, reducing lateral-movement exposure.
Agent ↔ control plane traffic is mutually authenticated and encrypted. Control commands, events, metrics and console streams share the same tunnel.
VNC/SPICE listeners are bound to 127.0.0.1 on each host. Console access is relayed through the authenticated tunnel and control plane session.
Enrollment tokens are cryptographically signed, single-use and expire automatically.
Every administrative action is recorded with actor, target, parameters, result and timestamp in an append-only log.
Available today vs roadmap
| Security Control | Status |
|---|---|
| mTLS agent tunnel | ✓ Available |
| No central host secrets | ✓ Available |
| Loopback-only consoles (127.0.0.1) | ✓ Available |
| Signed enrollment tokens | ✓ Available |
| Immutable audit log | ✓ Available |
| HA preflight guardrails | ✓ Available |
| Role-based access control (Platform Admin, VM Operator, Auditor) | Roadmap — Phase 11 |
| SSO via OIDC and SAML 2.0 (Okta, Keycloak, Entra ID) | Roadmap — Phase 11 |
| MFA: TOTP, FIDO2/WebAuthn | Roadmap — Phase 11 |
| SIEM log streaming (Splunk, Datadog, Elastic) | Roadmap — Phase 11 |
Supporting your compliance programme
| Framework | How VirtStack helps |
|---|---|
| ISO/IEC 27001 | Audit trail of admin actions; encrypted management plane; no shared host credentials |
| SOC 2 | Change evidence via audit log; HA visibility and fencing readiness |
| CERT-In directions (India) | Retainable logs of administrative activity; time-stamped events |
| India DPDP Act, 2023 | On-premise and air-gapped deployment keeps workload data within your infrastructure |
| PCI DSS | No inbound ports on hypervisors; console traffic confined to authenticated tunnel |
Responsible Disclosure
Report security concerns or vulnerabilities directly to our security engineering team at security@evomind.in.
