Andrew Mercer
on this page

KVM and libvirt overview

KVM (Kernel-based Virtual Machine) turns the Linux kernel into a hypervisor. Together with QEMU for device emulation and libvirt for management, it gives you full virtual machines with near-native CPU performance on any host whose processor has hardware virtualization extensions (Intel VT-x or AMD-V).

This page explains how the pieces fit together, the concepts you need before touching a command, how to choose between the common options, and where to find the detailed how-to for each task. Every other page in this section is linked from here.

Contents

The stack

  You:  virsh   virt-install   virt-manager   Cockpit   kvm-adm
              \        |            |            |        /
               +-------+------------+------------+-------+
                                    |
                            libvirt (libvirtd or the modular virtqemud/virtnetworkd/... daemons)
                     domains, networks, storage pools, snapshots, secrets
                                    |
                          QEMU process (one per running VM)
                      device emulation: virtio disk/net, serial, VNC/SPICE
                                    |
                     KVM kernel modules (kvm + kvm_intel or kvm_amd)  ->  /dev/kvm
                                    |
                          CPU virtualization extensions (VT-x / AMD-V)
Layer Role Where it shows up in these docs
KVM (kernel modules) Runs guest CPU instructions directly on the hardware; exposed as /dev/kvm Host setup, Nested virtualization
QEMU One process per VM. Emulates the motherboard and devices, and qemu-img manipulates disk images Storage, Import and convert, Disk resize
libvirt Stable management API and daemon. Stores each VM as an XML domain, manages networks and storage pools, applies security labels (SELinux/AppArmor) Manage VMs, Networking
Front ends virsh (CLI), virt-install (create), virt-clone, virt-manager (GUI), Cockpit (web), libguestfs tools (offline images) Tool reference, kvm-adm

Newer distributions may split libvirt into per-driver daemons (virtqemud, virtnetworkd, virtstoraged) instead of a single libvirtd; the commands in these docs work the same way against either. virsh version confirms that you can reach the daemon.

Core concepts

Domains

libvirt calls a VM a domain. A domain is defined (persistent XML config, survives reboots of the host) and either running or shut off. A domain can also be transient (running but not defined; it disappears when stopped).

  • The XML holds the CPU count, memory, disks, NICs, console and everything else. View it with virsh dumpxml vm01, change it with virsh edit vm01. See Manage VMs.
  • virsh destroy stops a domain immediately (like pulling the power cord). It does not delete anything. virsh undefine removes the definition, and with --remove-all-storage the disks. See Delete a VM.
  • Many changes have --config (persistent, applies on next boot) and --live (running VM only) variants. Use both to change a running VM and keep the change. See Change resources.

Connection URIs: system versus session

URI Runs as Images Typical use
qemu:///system root-owned libvirt daemon /var/lib/libvirt/images Servers, bridged networking, anything shared
qemu:///session your user ~/.local/share/libvirt/images Personal experiments; no root, but no bridging without extra setup

The two URIs see different sets of VMs. If virsh list --all looks empty, check which URI you are on (virsh uri). See Host setup.

Storage: images, volumes, pools

  • A disk image is a file (usually qcow2 or raw) that the guest sees as a block device (vda, vdb, ...).
  • A storage pool is a place libvirt keeps images, most simply a directory. default is normally /var/lib/libvirt/images. See Storage pools.
  • qcow2 gives you snapshots, thin provisioning and backing files; raw is fastest and simplest. See qcow2 vs raw.
  • Use the virtio bus for disks and NICs. It is far faster than emulated IDE/e1000 hardware and is supported out of the box by modern Linux guests.

Networking

  • default NAT network (virbr0): guests get private addresses via libvirt's dnsmasq and reach the outside through the host. Easy, but the LAN cannot reach the guests directly.
  • Bridge (br0): guests join the physical LAN with their own addresses. Needs host network configuration. See Bridged networking.
  • Every NIC has a MAC address. libvirt generates one from the 52:54:00 prefix; if you set one manually, make sure it does not match the host's (Troubleshooting).

Consoles and the guest agent

  • The serial console (virsh console) works over SSH with no GUI and needs console=ttyS0 on the guest kernel command line. The installer arguments in Create VMs set that up.
  • VNC/SPICE graphical consoles suit Windows and desktop guests (virt-viewer, virt-manager).
  • qemu-guest-agent, installed inside the guest, lets the host ask the VM for its IP addresses (virsh domifaddr --source agent) and quiesce filesystems. It is the most reliable way to find the address of a bridged guest (Find a VM's IP address).

Snapshots and templates

  • Snapshots (internal qcow2) capture disk state, optionally memory, and let you roll back. They live inside the image file, so they are not backups. See Snapshots.
  • Templates: build a base image once (or fetch one with virt-builder), clean it with virt-sysprep, then clone it. See Offline image tools and Clone.

Documentation map

Page What it covers Read it when
Host setup Hardware checks, installing KVM/libvirt on Ubuntu/Debian and RHEL/Fedora, the libvirt group, system versus session, SELinux and ACL fixes Building or repairing a hypervisor
Networking Default NAT network, bridges with netplan and NetworkManager, sysctls, finding guest IPs, adding and removing NICs Guests need LAN access, or you cannot find a guest's address
Storage and image formats qcow2 vs raw, creating and inspecting images, storage pools Before creating VMs or adding disks
Create VMs virt-install with kickstart or preseed, importing images, virt-builder templates, headless installs Making a new VM
Manage VMs Start, stop, autostart, inspect, console, edit XML, delete, clone, rename Day-to-day operations
Change resources Memory, vCPUs, attaching and detaching disks A VM needs more (or fewer) resources
Resize a disk Grow the image on the host, then the partition, LVM and filesystem in the guest A guest is out of disk space
Snapshots Create, list, revert, delete Before risky changes
Offline image tools virt-customize, virt-edit, guestfish, virt-sysprep, libguestfs errors Editing or repairing a disk image without booting it
Import and convert images raw, VDI, VMDK to qcow2, imaging a physical disk Migrating from other hypervisors or hardware
Remote access qemu+ssh://, virt-manager over X11, Cockpit Managing a headless host
Nested virtualization Checking and enabling nested KVM, CPU passthrough Labs that run hypervisors in VMs
Disk encryption LUKS in the guest, or in qcow2 via QEMU Protecting guest data at rest
Troubleshooting Symptom-to-fix table Something failed
Tool reference What every virsh/virt-*/qemu-img tool does Finding the right tool
kvm-adm The CLI that wraps all of the above You do not want to remember the commands

Typical workflows

1. Build a hypervisor

  1. Check the hardware and install packages: Host setup.
  2. Add your user to the libvirt group (permissions).
  3. Decide on networking. Either use the default NAT network or configure a bridge: Networking.
  4. Decide where images live (Storage pools); if that is not /var/lib/libvirt/images, apply the SELinux labelling.
  5. Verify: virt-host-validate qemu, virsh net-list --all, virsh pool-list --all (or kvm-adm host doctor).

2. Create the first VM

  1. Pick an install method with the decision guide below.
  2. Look up the --os-variant (osinfo-query os | grep -i debian).
  3. Run virt-install as shown in Create VMs.
  4. Find its address (Find a VM's IP address) and connect over SSH.
  5. Install qemu-guest-agent in the guest and enable autostart if the VM should come back after host reboots (Manage VMs).

3. Day-2 operations

Situation Steps
Risky change coming Snapshot, make the change, delete the snapshot when satisfied
Out of disk space Grow the image, then the partition and filesystem
Needs more RAM or CPU Change resources (applies on next boot)
Need a second identical VM Clone, after virt-sysprep if it is a template
Lost the root password virt-customize or guestfish on the shut-off image
Moving in a VM from VirtualBox/VMware Convert the image, then import it
Retiring a VM Delete with storage

Decision guides

System or session

Use qemu:///system unless you have a specific reason not to. It supports bridges, autostart at boot and shared storage. Use qemu:///session for throwaway VMs on a workstation where you do not have root.

NAT or bridge

Default NAT (virbr0) Bridge (br0)
Setup effort None Reconfigure the host NIC
Guests reachable from the LAN No (port-forward or use the host as a jump) Yes, as normal hosts
Addressing libvirt dnsmasq (192.168.122.0/24 by default) Your LAN's DHCP or static addressing
Find a guest's IP virsh net-dhcp-leases default Guest agent, or your DHCP server
Works with Wi-Fi host NICs Yes Generally no
Best for Labs, laptops, quick tests Servers that other machines must reach

qcow2 or raw

Pick qcow2 for almost everything: snapshots, thin provisioning, backing files and compression are worth the small overhead. Pick raw only for the last bit of I/O performance or when the storage layer already provides snapshots (LVM, ZFS, Ceph). Details: qcow2 vs raw.

Install method

Method Good for Details
ISO plus kickstart (RHEL family) or preseed (Debian family) Repeatable, unattended installs of a specific distribution Create VMs
Interactive with a serial console or VNC One-offs, Windows, unusual installers Install interactively
virt-builder template Fastest way to a fresh Linux VM with an SSH key and known root password Build from a template
Import an existing disk image Cloud images, migrated VMs, restored backups Import, Convert
Clone More VMs like one you already have Clone

Resize online or offline

Online (virsh blockresize) Offline (qemu-img resize)
VM state Running Shut off
Size argument Absolute (50G is the new total) Absolute or relative (+30G)
Guest sees the change Immediately After boot

Either way the partition and filesystem inside the guest still need growing: Resize a disk. Growing is routine; shrinking is risky and should be avoided.

Snapshot or backup

A snapshot is a quick rollback point stored in the same file as the disk. It protects against a bad upgrade, not against losing the file or the host. For real backups copy the image (or use qemu-img convert to a compressed copy) to different storage while the VM is shut off or after quiescing it with the guest agent.

Task index

I want to... Go to
Check my CPU supports virtualization Host setup
Fix authentication unavailable: no polkit agent Permissions
Fix Permission denied opening an ISO or image SELinux and ACLs
Restore the missing default network Default NAT network
Put guests on my LAN Bridged networking
Find a guest's IP address Find a VM's IP address
Add a second NIC Add or remove a NIC
Create a disk image Create images
Check an image for corruption Inspect and check
Create a storage pool on another disk Storage pools
Install a VM unattended Kickstart, preseed
Spin up a Linux VM in one minute virt-builder
Enter the console of a headless VM Details
Edit a VM's hardware definition Edit the definition
Delete a VM and its disk Delete a VM
Clone or rename a VM Clone, Rename
Change memory or vCPUs Memory, vCPUs
Add or remove a disk Add or remove a disk
Grow a full disk Resize a disk
Make LVM see the new space Step 3b: LVM
Snapshot before an upgrade Snapshots
Reset a forgotten root password Offline image tools
Fix libguestfs: error messages libguestfs troubleshooting
Convert a VirtualBox or VMware disk Convert between formats
Manage a remote host libvirt over SSH
Run KVM inside a VM Nested virtualization
Encrypt a guest's disk Disk encryption
Decode an error message Troubleshooting
Look up what a tool does Tool reference

Command cheat sheet

The five commands that cover most of the work, each with its kvm-adm equivalent (see kvm-adm for all of them).

Tool Common commands
virsh list --all, start, shutdown, destroy, console, edit, dominfo, domblklist, domiflist, domifaddr, net-list, net-dhcp-leases, snapshot-create-as, snapshot-revert, undefine, blockresize, attach-disk, attach-interface, setmaxmem, setmem
virt-install --name --memory --vcpus --disk --network --location --extra-args --import --os-variant
virt-clone --original --name --auto-clone
qemu-img create, info, check, resize, convert
libguestfs virt-customize, virt-edit, virt-builder, virt-sysprep, guestfish
Purpose Raw command kvm-adm
List virsh list --all kvm-adm ls
Details virsh dominfo vm01 kvm-adm info vm01
IP address virsh domifaddr vm01 --source agent kvm-adm ip vm01
Resize virsh blockresize vm01 vda 50G kvm-adm disk resize vm01 vda 50G
Snapshot virsh snapshot-create-as --domain vm01 --name n kvm-adm snap create vm01 n
Delete virsh undefine vm01 --remove-all-storage ... kvm-adm delete vm01

Rules of thumb and common pitfalls

  1. destroy is not delete. It powers the VM off. Deleting is undefine, with --remove-all-storage to remove disks (Delete a VM).
  2. blockresize takes the new total size, not an increment, whereas qemu-img resize +N adds (Resize a disk).
  3. A resized disk is not a resized filesystem. Grow the partition, then LVM (partition first, then pvresize), then the filesystem. A reboot alone does nothing.
  4. Attach qcow2 files with --subdriver qcow2, otherwise libvirt treats them as raw (Add or remove a disk).
  5. Use virsh edit, not the files in /etc/libvirt/qemu/. libvirt regenerates them, and edit validates your changes.
  6. Memory and vCPU changes with --config apply on next boot. Maximum memory can only be changed with the VM shut off (Change resources).
  7. Never let a guest share the host's MAC address. Symptom: guest has no network (Troubleshooting).
  8. Offline image tools need a shut-off VM. Two guests writing one image corrupts it (Offline image tools).
  9. Snapshots are not backups. They live in the same file as the disk (Snapshots).
  10. Custom image directories need SELinux labels, and ISOs in a home directory need an ACL for the qemu user (Host setup).
  11. Take an XML backup before hand-editing (virsh dumpxml vm01 > vm01.xml.bak), and validate with virt-xml-validate.
  12. Test destructive commands with kvm-adm --dry-run before running them for real.

kvm-adm: one CLI for all of it

kvm-adm is a Rust command-line tool that folds the commands in these documents into one binary, with sensible defaults from ~/.kvm-adm.conf:

kvm-adm host doctor                                    # check the host
kvm-adm create web01 -l rhel-9.iso --kickstart http://192.0.2.50:8000/ks.cfg
kvm-adm ip web01                                       # guest agent, then lease, then ARP
kvm-adm disk add web01 50G                             # create, attach with the right driver
kvm-adm disk resize web01 vda 80G                      # online or offline, prints guest steps
kvm-adm snap create web01 before-upgrade
kvm-adm -n delete web01                                # dry run: shows what would be removed

It calls the real tools underneath, so the manual pages here always apply. Full reference: kvm-adm.

Glossary

Term Meaning
Domain libvirt's name for a virtual machine
Guest / host The VM and the hypervisor machine it runs on
Hypervisor Software (here KVM+QEMU) that runs VMs
qcow2 QEMU Copy-On-Write v2 image format: thin provisioned, supports snapshots and backing files
raw Plain block-for-block disk image
Backing file A read-only base image that a qcow2 overlay stores changes against
virtio Paravirtualized devices (disk, network, balloon, ...) that are much faster than emulated hardware
virbr0 Bridge for libvirt's default NAT network
Bridge (br0) Host network bridge that connects guests directly to the physical LAN
Storage pool libvirt-managed location for disk images (directory, LVM, NFS, ...)
Managed save State saved by virsh managedsave; blocks undefine unless removed
NVRAM Per-VM UEFI variable store; must be removed together with a UEFI domain
osinfo / os-variant Database of OS defaults used by virt-install --os-variant
Kickstart / preseed Answer files for unattended RHEL-family / Debian-family installs
libguestfs Library and tools that open disk images offline
qemu-guest-agent Daemon inside the guest that lets the host query IPs and quiesce filesystems
Nested virtualization Running KVM inside a KVM guest

Scope and further reading

These pages cover single-host KVM administration from the command line. They do not cover live migration, clustering (oVirt, Proxmox, OpenStack), GPU or PCI passthrough, or libvirt's SR-IOV networking. Upstream documentation: