KVM and libvirt overview¶
KVM (Kernel-based Virtual Machine) turns the Linux kernel into a hypervisor. Together with QEMU for device emulation and libvirt for management, it gives you full virtual machines with near-native CPU performance on any host whose processor has hardware virtualization extensions (Intel VT-x or AMD-V).
This page explains how the pieces fit together, the concepts you need before touching a command, how to choose between the common options, and where to find the detailed how-to for each task. Every other page in this section is linked from here.
Contents¶
- The stack
- Core concepts
- Documentation map
- Typical workflows
- Decision guides
- Task index
- Command cheat sheet
- Rules of thumb and common pitfalls
- kvm-adm: one CLI for all of it
- Glossary
- Scope and further reading
The stack¶
You: virsh virt-install virt-manager Cockpit kvm-adm
\ | | | /
+-------+------------+------------+-------+
|
libvirt (libvirtd or the modular virtqemud/virtnetworkd/... daemons)
domains, networks, storage pools, snapshots, secrets
|
QEMU process (one per running VM)
device emulation: virtio disk/net, serial, VNC/SPICE
|
KVM kernel modules (kvm + kvm_intel or kvm_amd) -> /dev/kvm
|
CPU virtualization extensions (VT-x / AMD-V)
| Layer | Role | Where it shows up in these docs |
|---|---|---|
| KVM (kernel modules) | Runs guest CPU instructions directly on the hardware; exposed as /dev/kvm |
Host setup, Nested virtualization |
| QEMU | One process per VM. Emulates the motherboard and devices, and qemu-img manipulates disk images |
Storage, Import and convert, Disk resize |
| libvirt | Stable management API and daemon. Stores each VM as an XML domain, manages networks and storage pools, applies security labels (SELinux/AppArmor) | Manage VMs, Networking |
| Front ends | virsh (CLI), virt-install (create), virt-clone, virt-manager (GUI), Cockpit (web), libguestfs tools (offline images) |
Tool reference, kvm-adm |
Newer distributions may split libvirt into per-driver daemons (virtqemud, virtnetworkd, virtstoraged) instead of a single libvirtd; the commands in these docs work the same way against either. virsh version confirms that you can reach the daemon.
Core concepts¶
Domains¶
libvirt calls a VM a domain. A domain is defined (persistent XML config, survives reboots of the host) and either running or shut off. A domain can also be transient (running but not defined; it disappears when stopped).
- The XML holds the CPU count, memory, disks, NICs, console and everything else. View it with
virsh dumpxml vm01, change it withvirsh edit vm01. See Manage VMs. virsh destroystops a domain immediately (like pulling the power cord). It does not delete anything.virsh undefineremoves the definition, and with--remove-all-storagethe disks. See Delete a VM.- Many changes have
--config(persistent, applies on next boot) and--live(running VM only) variants. Use both to change a running VM and keep the change. See Change resources.
Connection URIs: system versus session¶
| URI | Runs as | Images | Typical use |
|---|---|---|---|
qemu:///system |
root-owned libvirt daemon | /var/lib/libvirt/images |
Servers, bridged networking, anything shared |
qemu:///session |
your user | ~/.local/share/libvirt/images |
Personal experiments; no root, but no bridging without extra setup |
The two URIs see different sets of VMs. If virsh list --all looks empty, check which URI you are on (virsh uri). See Host setup.
Storage: images, volumes, pools¶
- A disk image is a file (usually qcow2 or raw) that the guest sees as a block device (
vda,vdb, ...). - A storage pool is a place libvirt keeps images, most simply a directory.
defaultis normally/var/lib/libvirt/images. See Storage pools. - qcow2 gives you snapshots, thin provisioning and backing files; raw is fastest and simplest. See qcow2 vs raw.
- Use the virtio bus for disks and NICs. It is far faster than emulated IDE/e1000 hardware and is supported out of the box by modern Linux guests.
Networking¶
defaultNAT network (virbr0): guests get private addresses via libvirt's dnsmasq and reach the outside through the host. Easy, but the LAN cannot reach the guests directly.- Bridge (
br0): guests join the physical LAN with their own addresses. Needs host network configuration. See Bridged networking. - Every NIC has a MAC address. libvirt generates one from the
52:54:00prefix; if you set one manually, make sure it does not match the host's (Troubleshooting).
Consoles and the guest agent¶
- The serial console (
virsh console) works over SSH with no GUI and needsconsole=ttyS0on the guest kernel command line. The installer arguments in Create VMs set that up. - VNC/SPICE graphical consoles suit Windows and desktop guests (
virt-viewer,virt-manager). - qemu-guest-agent, installed inside the guest, lets the host ask the VM for its IP addresses (
virsh domifaddr --source agent) and quiesce filesystems. It is the most reliable way to find the address of a bridged guest (Find a VM's IP address).
Snapshots and templates¶
- Snapshots (internal qcow2) capture disk state, optionally memory, and let you roll back. They live inside the image file, so they are not backups. See Snapshots.
- Templates: build a base image once (or fetch one with
virt-builder), clean it withvirt-sysprep, then clone it. See Offline image tools and Clone.
Documentation map¶
| Page | What it covers | Read it when |
|---|---|---|
| Host setup | Hardware checks, installing KVM/libvirt on Ubuntu/Debian and RHEL/Fedora, the libvirt group, system versus session, SELinux and ACL fixes |
Building or repairing a hypervisor |
| Networking | Default NAT network, bridges with netplan and NetworkManager, sysctls, finding guest IPs, adding and removing NICs | Guests need LAN access, or you cannot find a guest's address |
| Storage and image formats | qcow2 vs raw, creating and inspecting images, storage pools | Before creating VMs or adding disks |
| Create VMs | virt-install with kickstart or preseed, importing images, virt-builder templates, headless installs |
Making a new VM |
| Manage VMs | Start, stop, autostart, inspect, console, edit XML, delete, clone, rename | Day-to-day operations |
| Change resources | Memory, vCPUs, attaching and detaching disks | A VM needs more (or fewer) resources |
| Resize a disk | Grow the image on the host, then the partition, LVM and filesystem in the guest | A guest is out of disk space |
| Snapshots | Create, list, revert, delete | Before risky changes |
| Offline image tools | virt-customize, virt-edit, guestfish, virt-sysprep, libguestfs errors |
Editing or repairing a disk image without booting it |
| Import and convert images | raw, VDI, VMDK to qcow2, imaging a physical disk | Migrating from other hypervisors or hardware |
| Remote access | qemu+ssh://, virt-manager over X11, Cockpit |
Managing a headless host |
| Nested virtualization | Checking and enabling nested KVM, CPU passthrough | Labs that run hypervisors in VMs |
| Disk encryption | LUKS in the guest, or in qcow2 via QEMU | Protecting guest data at rest |
| Troubleshooting | Symptom-to-fix table | Something failed |
| Tool reference | What every virsh/virt-*/qemu-img tool does |
Finding the right tool |
| kvm-adm | The CLI that wraps all of the above | You do not want to remember the commands |
Typical workflows¶
1. Build a hypervisor¶
- Check the hardware and install packages: Host setup.
- Add your user to the
libvirtgroup (permissions). - Decide on networking. Either use the
defaultNAT network or configure a bridge: Networking. - Decide where images live (Storage pools); if that is not
/var/lib/libvirt/images, apply the SELinux labelling. - Verify:
virt-host-validate qemu,virsh net-list --all,virsh pool-list --all(orkvm-adm host doctor).
2. Create the first VM¶
- Pick an install method with the decision guide below.
- Look up the
--os-variant(osinfo-query os | grep -i debian). - Run
virt-installas shown in Create VMs. - Find its address (Find a VM's IP address) and connect over SSH.
- Install
qemu-guest-agentin the guest and enable autostart if the VM should come back after host reboots (Manage VMs).
3. Day-2 operations¶
| Situation | Steps |
|---|---|
| Risky change coming | Snapshot, make the change, delete the snapshot when satisfied |
| Out of disk space | Grow the image, then the partition and filesystem |
| Needs more RAM or CPU | Change resources (applies on next boot) |
| Need a second identical VM | Clone, after virt-sysprep if it is a template |
| Lost the root password | virt-customize or guestfish on the shut-off image |
| Moving in a VM from VirtualBox/VMware | Convert the image, then import it |
| Retiring a VM | Delete with storage |
Decision guides¶
System or session¶
Use qemu:///system unless you have a specific reason not to. It supports bridges, autostart at boot and shared storage. Use qemu:///session for throwaway VMs on a workstation where you do not have root.
NAT or bridge¶
Default NAT (virbr0) |
Bridge (br0) |
|
|---|---|---|
| Setup effort | None | Reconfigure the host NIC |
| Guests reachable from the LAN | No (port-forward or use the host as a jump) | Yes, as normal hosts |
| Addressing | libvirt dnsmasq (192.168.122.0/24 by default) | Your LAN's DHCP or static addressing |
| Find a guest's IP | virsh net-dhcp-leases default |
Guest agent, or your DHCP server |
| Works with Wi-Fi host NICs | Yes | Generally no |
| Best for | Labs, laptops, quick tests | Servers that other machines must reach |
qcow2 or raw¶
Pick qcow2 for almost everything: snapshots, thin provisioning, backing files and compression are worth the small overhead. Pick raw only for the last bit of I/O performance or when the storage layer already provides snapshots (LVM, ZFS, Ceph). Details: qcow2 vs raw.
Install method¶
| Method | Good for | Details |
|---|---|---|
| ISO plus kickstart (RHEL family) or preseed (Debian family) | Repeatable, unattended installs of a specific distribution | Create VMs |
| Interactive with a serial console or VNC | One-offs, Windows, unusual installers | Install interactively |
virt-builder template |
Fastest way to a fresh Linux VM with an SSH key and known root password | Build from a template |
| Import an existing disk image | Cloud images, migrated VMs, restored backups | Import, Convert |
| Clone | More VMs like one you already have | Clone |
Resize online or offline¶
Online (virsh blockresize) |
Offline (qemu-img resize) |
|
|---|---|---|
| VM state | Running | Shut off |
| Size argument | Absolute (50G is the new total) |
Absolute or relative (+30G) |
| Guest sees the change | Immediately | After boot |
Either way the partition and filesystem inside the guest still need growing: Resize a disk. Growing is routine; shrinking is risky and should be avoided.
Snapshot or backup¶
A snapshot is a quick rollback point stored in the same file as the disk. It protects against a bad upgrade, not against losing the file or the host. For real backups copy the image (or use qemu-img convert to a compressed copy) to different storage while the VM is shut off or after quiescing it with the guest agent.
Task index¶
| I want to... | Go to |
|---|---|
| Check my CPU supports virtualization | Host setup |
Fix authentication unavailable: no polkit agent |
Permissions |
Fix Permission denied opening an ISO or image |
SELinux and ACLs |
Restore the missing default network |
Default NAT network |
| Put guests on my LAN | Bridged networking |
| Find a guest's IP address | Find a VM's IP address |
| Add a second NIC | Add or remove a NIC |
| Create a disk image | Create images |
| Check an image for corruption | Inspect and check |
| Create a storage pool on another disk | Storage pools |
| Install a VM unattended | Kickstart, preseed |
| Spin up a Linux VM in one minute | virt-builder |
| Enter the console of a headless VM | Details |
| Edit a VM's hardware definition | Edit the definition |
| Delete a VM and its disk | Delete a VM |
| Clone or rename a VM | Clone, Rename |
| Change memory or vCPUs | Memory, vCPUs |
| Add or remove a disk | Add or remove a disk |
| Grow a full disk | Resize a disk |
| Make LVM see the new space | Step 3b: LVM |
| Snapshot before an upgrade | Snapshots |
| Reset a forgotten root password | Offline image tools |
Fix libguestfs: error messages |
libguestfs troubleshooting |
| Convert a VirtualBox or VMware disk | Convert between formats |
| Manage a remote host | libvirt over SSH |
| Run KVM inside a VM | Nested virtualization |
| Encrypt a guest's disk | Disk encryption |
| Decode an error message | Troubleshooting |
| Look up what a tool does | Tool reference |
Command cheat sheet¶
The five commands that cover most of the work, each with its kvm-adm equivalent (see kvm-adm for all of them).
| Tool | Common commands |
|---|---|
virsh |
list --all, start, shutdown, destroy, console, edit, dominfo, domblklist, domiflist, domifaddr, net-list, net-dhcp-leases, snapshot-create-as, snapshot-revert, undefine, blockresize, attach-disk, attach-interface, setmaxmem, setmem |
virt-install |
--name --memory --vcpus --disk --network --location --extra-args --import --os-variant |
virt-clone |
--original --name --auto-clone |
qemu-img |
create, info, check, resize, convert |
| libguestfs | virt-customize, virt-edit, virt-builder, virt-sysprep, guestfish |
| Purpose | Raw command | kvm-adm |
|---|---|---|
| List | virsh list --all |
kvm-adm ls |
| Details | virsh dominfo vm01 |
kvm-adm info vm01 |
| IP address | virsh domifaddr vm01 --source agent |
kvm-adm ip vm01 |
| Resize | virsh blockresize vm01 vda 50G |
kvm-adm disk resize vm01 vda 50G |
| Snapshot | virsh snapshot-create-as --domain vm01 --name n |
kvm-adm snap create vm01 n |
| Delete | virsh undefine vm01 --remove-all-storage ... |
kvm-adm delete vm01 |
Rules of thumb and common pitfalls¶
destroyis not delete. It powers the VM off. Deleting isundefine, with--remove-all-storageto remove disks (Delete a VM).blockresizetakes the new total size, not an increment, whereasqemu-img resize +Nadds (Resize a disk).- A resized disk is not a resized filesystem. Grow the partition, then LVM (partition first, then
pvresize), then the filesystem. A reboot alone does nothing. - Attach qcow2 files with
--subdriver qcow2, otherwise libvirt treats them as raw (Add or remove a disk). - Use
virsh edit, not the files in/etc/libvirt/qemu/. libvirt regenerates them, andeditvalidates your changes. - Memory and vCPU changes with
--configapply on next boot. Maximum memory can only be changed with the VM shut off (Change resources). - Never let a guest share the host's MAC address. Symptom: guest has no network (Troubleshooting).
- Offline image tools need a shut-off VM. Two guests writing one image corrupts it (Offline image tools).
- Snapshots are not backups. They live in the same file as the disk (Snapshots).
- Custom image directories need SELinux labels, and ISOs in a home directory need an ACL for the
qemuuser (Host setup). - Take an XML backup before hand-editing (
virsh dumpxml vm01 > vm01.xml.bak), and validate withvirt-xml-validate. - Test destructive commands with
kvm-adm --dry-runbefore running them for real.
kvm-adm: one CLI for all of it¶
kvm-adm is a Rust command-line tool that folds the commands in these documents into one binary, with sensible defaults from ~/.kvm-adm.conf:
kvm-adm host doctor # check the host
kvm-adm create web01 -l rhel-9.iso --kickstart http://192.0.2.50:8000/ks.cfg
kvm-adm ip web01 # guest agent, then lease, then ARP
kvm-adm disk add web01 50G # create, attach with the right driver
kvm-adm disk resize web01 vda 80G # online or offline, prints guest steps
kvm-adm snap create web01 before-upgrade
kvm-adm -n delete web01 # dry run: shows what would be removed
It calls the real tools underneath, so the manual pages here always apply. Full reference: kvm-adm.
Glossary¶
| Term | Meaning |
|---|---|
| Domain | libvirt's name for a virtual machine |
| Guest / host | The VM and the hypervisor machine it runs on |
| Hypervisor | Software (here KVM+QEMU) that runs VMs |
| qcow2 | QEMU Copy-On-Write v2 image format: thin provisioned, supports snapshots and backing files |
| raw | Plain block-for-block disk image |
| Backing file | A read-only base image that a qcow2 overlay stores changes against |
| virtio | Paravirtualized devices (disk, network, balloon, ...) that are much faster than emulated hardware |
| virbr0 | Bridge for libvirt's default NAT network |
Bridge (br0) |
Host network bridge that connects guests directly to the physical LAN |
| Storage pool | libvirt-managed location for disk images (directory, LVM, NFS, ...) |
| Managed save | State saved by virsh managedsave; blocks undefine unless removed |
| NVRAM | Per-VM UEFI variable store; must be removed together with a UEFI domain |
| osinfo / os-variant | Database of OS defaults used by virt-install --os-variant |
| Kickstart / preseed | Answer files for unattended RHEL-family / Debian-family installs |
| libguestfs | Library and tools that open disk images offline |
| qemu-guest-agent | Daemon inside the guest that lets the host query IPs and quiesce filesystems |
| Nested virtualization | Running KVM inside a KVM guest |
Scope and further reading¶
These pages cover single-host KVM administration from the command line. They do not cover live migration, clustering (oVirt, Proxmox, OpenStack), GPU or PCI passthrough, or libvirt's SR-IOV networking. Upstream documentation:
- KVM project: https://www.linux-kvm.org/page/Main_Page
- libvirt: https://libvirt.org/docs.html and the domain XML format at https://libvirt.org/formatdomain.html
- libguestfs: https://libguestfs.org
- QEMU
qemu-img: https://www.qemu.org/docs/master/tools/qemu-img.html