The enterprise control plane for Linux/KVM virtualization
SLES + KVM + SUSE HA underneath. VirtStack on top.
VirtStack is an enterprise virtualization management platform for KVM hypervisors running on SUSE Linux Enterprise Server (SLES). It gives your team one web console for every host and VM — without storing a single root password or SSH key centrally, and without opening a single inbound port on your hypervisors.
KVM is not the problem. The enterprise operations around KVM are — and that's what VirtStack solves. It replaces none of the components below it: your SUSE subscriptions, support model and Linux skills stay where they are.
Central root secrets
Preflight safety gate
Outbound mTLS tunnel
Free evaluation
Powered by the open enterprise stack
Why infrastructure teams choose VirtStack
Legacy KVM tooling forces a trade-off: script everything with virsh over SSH, or hand a central server the keys to every host. VirtStack removes that trade-off.
| If your current setup… | VirtStack gives you… |
|---|---|
Stores root SSH keys or passwords on a management server | Zero central secrets — agents authenticate outbound with mutual TLS |
Needs VNC/SSH ports opened across firewalls | One outbound tunnel carrying control and console traffic |
Copies multi-GB images for every new VM | Linked clones provisioned in seconds via copy-on-write QCOW2 overlays |
Produces cloned VMs with duplicate MACs and machine IDs | Automatic identity regeneration on every clone |
Relies on brittle shell scripts | Native libvirt RPC executed locally on each hypervisor |
For CIOs and CTOs: Measurable Business Outcomes
Built for the way infrastructure teams actually work
Six architectural foundations engineered for Day-2 enterprise reliability.
1. Secure by architecture, not configuration
Every hypervisor runs a lightweight VirtStack agent that dials out to the control plane over an encrypted, mutually authenticated tunnel. Hosts behind NAT or strict egress-only firewalls enroll without network changes.
- No inbound ports on hypervisors
- VM consoles bound to 127.0.0.1
- Time-bounded, signed enrollment tokens
2. Complete VM lifecycle in the browser
Create, start, gracefully shut down, force off, reboot, pause, resume and delete VMs. Every provisioning request passes a 16-point preflight gate that checks RAM headroom, CPU overcommit, datastore capacity and bridge availability before anything is submitted to the host.
- Start / Stop / Pause / Resume / Delete
- 16-point preflight safety gate
- noVNC console over encrypted tunnel
3. Deep virtual hardware control
Tune vCPU topology and CPU models, memory and ballooning, disks and NICs, and pass through physical USB and PCIe/GPU (VFIO) devices.
- vTPM 2.0 for Windows 11 & BitLocker
- VirtIO RNG for guest entropy
- i6300esb hung-guest watchdogs
4. Snapshots & clones that respect your storage
Disk and memory snapshots, full clones, instant linked clones, clone-from-snapshot and live disk flattening — with full visibility into backing chains so you never delete a base image a VM still depends on.
- Instant linked clones via QCOW2 overlays
- Automatic identity regeneration on clone
- Live disk flattening with chain visibility
5. NUMA-aware placement
A two-stage placement engine filters and scores hosts, then pins vCPUs and memory to NUMA nodes with strict, preferred or interleave policies. Every decision is logged with the reason a host was chosen or rejected.
- Two-stage filter & score engine
- strict · preferred · interleave policies
- Full decision log on every placement
6. Real-time observability and HA visibility
Per-second host, VM and NUMA metrics pushed over WebSockets. For SUSE Linux Enterprise High Availability clusters, VirtStack shows Pacemaker/Corosync state, quorum and SBD fencing readiness.
- Per-second metrics over WebSockets
- Pacemaker / Corosync / SBD state
- HA-safe operation gating
The 16-point preflight validation simulator
Every VM action is validated against capacity, overcommit thresholds, and cluster safety before anything reaches the host.
16-Point Preflight Gate Interactive Simulator
VirtStack validates host headroom, CPU overcommit, datastore capacity & bridges before submitting to libvirt.
Where enterprise teams start
Whether you're modernizing from VMware, running SAP, or building dev/test pipelines — VirtStack adapts to your workloads.
VMware Modernization
A disciplined Assess → Plan → Migrate → Validate → Operate → Optimize path, with rollback built in at every stage using virt-v2v.
SAP on SUSE KVM
Two HA layers in one view: Pacemaker restarts general-purpose VMs; HANA System Replication protects the database. NUMA guardrails throughout.
Dev / Test Environments
Templates and instant linked clones deliver environments in seconds with near-zero additional storage — consistent builds every time.
Data-Centre & MSPs
Many KVM clusters and NATed customer sites, one console. Manage diverse estates centrally without opening a single inbound firewall port.
Open source is not zero cost.
Subscriptions, licensing, skills and migration effort are real. We build a TCO model with you instead of quoting savings percentages.
Reference architecture & Operating Model
Build once with YaST & crmsh. Operate every day from the VirtStack web console.
SUSE KVM Cluster & Pacemaker Live Control
Real-time Pacemaker/Corosync Quorum: 3 Nodes Online (Quorate) · Zero Central Root Secrets
SUSE Linux Enterprise Server 15 SP7
64 Sockets (2x Intel Xeon Platinum 8480+)
Node 0: Cores 0-31 | Node 1: Cores 32-63
Fencing ready (/dev/disk/by-id/sbd-san-vol0)
Connected (Outbound mTLS Tunnel active)
vCPU: 32 Cores · Memory: 256GB (NUMA Node 0)
vCPU: 8 Cores · Memory: 32GB
vCPU: 4 Cores · Memory: 16GB
Platform engineering with YaST, zypper, crmsh
- Servers, SLES + KVM, networks
- Storage, Pacemaker, Corosync, SBD
- Built once with standard SUSE tooling
VirtStack-assisted onboarding
- One-line host enrollment
- Hardware & NUMA discovery
- Golden templates, adopt existing VMs
VirtStack's core Day-2 focus
- VM lifecycle, console, snapshots
- NUMA placement, HA visibility
- Live metrics, maintenance, audit trail
Designed so the server holds zero root secrets
Most virtualization managers become the single most valuable target on the network: one server holding root credentials to every hypervisor. VirtStack is designed so that server holds none.
No root passwords, SSH private keys or libvirt TCP credentials stored on the control plane. Each agent authenticates with its own certificate issued at enrollment. Revoking a host revokes only that host’s certificate.
Agents open an outbound TLS connection; no inbound listener is required on hosts. Works behind NAT and egress-only firewalls, reducing lateral-movement exposure.
Agent ↔ control plane traffic is mutually authenticated and encrypted. Control commands, events, metrics and console streams share the same tunnel.
VNC/SPICE listeners are bound to 127.0.0.1 on each host. Console access is relayed through the authenticated tunnel and control plane session.
Enrollment tokens are cryptographically signed, single-use and expire automatically after an admin-configured validity period.
Every administrative action is recorded with actor, target, parameters, result and timestamp in an append-only log.
Supporting Your Enterprise Compliance Programme
| Framework | How VirtStack Supports It |
|---|---|
| ISO/IEC 27001 | Append-only audit trail; encrypted management plane; no shared host credentials. |
| SOC 2 Type II | Automated operational logs; mutual TLS on all communications; least-privilege service design. |
| DORA / NIS 2 (EU) | Resilient multi-cluster architecture; no central point of cryptographic failure; fast recovery pathways. |
| PCI-DSS v4.0 | Hypervisor consoles bound to 127.0.0.1; zero external listeners on virtualization hosts. |
Questions about VirtStack & SLES KVM
Straightforward technical answers to the most common architectural and commercial questions.
Try VirtStack on your own hardware
Enroll your first SUSE Linux Enterprise KVM host in minutes. 60-day full license, 4 sockets included.
Hands-on Engineers
60-day licence, up to 4 sockets, full installation documentation.
Architects & Teams
45-minute live session with an engineer tailored to your use case.
CTOs & Procurement
Pricing, procurement, SUSE subscription bundling and custom SLAs.
