Enterprise-Grade · Open Stack · Zero Trust

The enterprise control plane for Linux/KVM virtualization

SLES + KVM + SUSE HA underneath. VirtStack on top.

VirtStack is an enterprise virtualization management platform for KVM hypervisors running on SUSE Linux Enterprise Server (SLES). It gives your team one web console for every host and VM — without storing a single root password or SSH key centrally, and without opening a single inbound port on your hypervisors.

KVM is not the problem. The enterprise operations around KVM are — and that's what VirtStack solves. It replaces none of the components below it: your SUSE subscriptions, support model and Linux skills stay where they are.

0

Central root secrets

16-Pt

Preflight safety gate

100%

Outbound mTLS tunnel

60-Day

Free evaluation

Powered by the open enterprise stack

SUSE Linux Enterprise
KVM
QEMU
libvirt
Pacemaker
Corosync
SBD Fencing
noVNC
mTLS
NUMA Pinning
VFIO / GPU
vTPM 2.0
QCOW2 Clones
VirtIO RNG
LVM Storage
WebSocket Metrics
SUSE Linux Enterprise
KVM
QEMU
libvirt
Pacemaker
Corosync
SBD Fencing
noVNC
mTLS
NUMA Pinning
VFIO / GPU
vTPM 2.0
QCOW2 Clones
VirtIO RNG
LVM Storage
WebSocket Metrics
Platform Overview

Why infrastructure teams choose VirtStack

Legacy KVM tooling forces a trade-off: script everything with virsh over SSH, or hand a central server the keys to every host. VirtStack removes that trade-off.

If your current setup…VirtStack gives you…
Stores root SSH keys or passwords on a management server
Zero central secrets — agents authenticate outbound with mutual TLS
Needs VNC/SSH ports opened across firewalls
One outbound tunnel carrying control and console traffic
Copies multi-GB images for every new VM
Linked clones provisioned in seconds via copy-on-write QCOW2 overlays
Produces cloned VMs with duplicate MACs and machine IDs
Automatic identity regeneration on every clone
Relies on brittle shell scripts
Native libvirt RPC executed locally on each hypervisor

For CIOs and CTOs: Measurable Business Outcomes

✅
Choice
Open stack: SLES, KVM, Pacemaker
Less single-vendor dependency
⚡
Efficiency
One console, live event stream
Less time per change and per incident
🛡️
Risk Reduction
Preflight, HA safeguards, audit log
Fewer failed changes; audit-ready
🚀
Speed
Templates, instant linked clones
Faster project delivery
📐
Standards
Placement engine, NUMA policies
Consistent service quality
Core Capabilities

Built for the way infrastructure teams actually work

Six architectural foundations engineered for Day-2 enterprise reliability.

1. Secure by architecture, not configuration

Every hypervisor runs a lightweight VirtStack agent that dials out to the control plane over an encrypted, mutually authenticated tunnel. Hosts behind NAT or strict egress-only firewalls enroll without network changes.

  • No inbound ports on hypervisors
  • VM consoles bound to 127.0.0.1
  • Time-bounded, signed enrollment tokens

2. Complete VM lifecycle in the browser

Create, start, gracefully shut down, force off, reboot, pause, resume and delete VMs. Every provisioning request passes a 16-point preflight gate that checks RAM headroom, CPU overcommit, datastore capacity and bridge availability before anything is submitted to the host.

  • Start / Stop / Pause / Resume / Delete
  • 16-point preflight safety gate
  • noVNC console over encrypted tunnel

3. Deep virtual hardware control

Tune vCPU topology and CPU models, memory and ballooning, disks and NICs, and pass through physical USB and PCIe/GPU (VFIO) devices.

  • vTPM 2.0 for Windows 11 & BitLocker
  • VirtIO RNG for guest entropy
  • i6300esb hung-guest watchdogs

4. Snapshots & clones that respect your storage

Disk and memory snapshots, full clones, instant linked clones, clone-from-snapshot and live disk flattening — with full visibility into backing chains so you never delete a base image a VM still depends on.

  • Instant linked clones via QCOW2 overlays
  • Automatic identity regeneration on clone
  • Live disk flattening with chain visibility

5. NUMA-aware placement

A two-stage placement engine filters and scores hosts, then pins vCPUs and memory to NUMA nodes with strict, preferred or interleave policies. Every decision is logged with the reason a host was chosen or rejected.

  • Two-stage filter & score engine
  • strict · preferred · interleave policies
  • Full decision log on every placement

6. Real-time observability and HA visibility

Per-second host, VM and NUMA metrics pushed over WebSockets. For SUSE Linux Enterprise High Availability clusters, VirtStack shows Pacemaker/Corosync state, quorum and SBD fencing readiness.

  • Per-second metrics over WebSockets
  • Pacemaker / Corosync / SBD state
  • HA-safe operation gating
Interactive Safety Gate

The 16-point preflight validation simulator

Every VM action is validated against capacity, overcommit thresholds, and cluster safety before anything reaches the host.

16-Point Preflight Gate Interactive Simulator

VirtStack validates host headroom, CPU overcommit, datastore capacity & bridges before submitting to libvirt.

16 / 16 PASSED
Requested RAM:32 GB
Host Free: 128 GB (Max recommended)
Requested vCPUs:8 Cores
Overcommit limit: 32 Cores
Storage Capacity:100 GB
Pool Free: 500 GB
01.Host RAM headroom check (non-ballooned physical RAM available)
02.CPU overcommit ratio threshold check (<= 4:1 ratio)
03.Datastore volume storage capacity validation
04.Host network bridge interface availability (br0)
05.NUMA node alignment & vCPU pinning validation
06.libvirt domain XML schema compliance
07.QEMU binary & SLES 15 SP7 kernel capability check
08.AppArmor mandatory access control profile readiness
09.vTPM 2.0 swtpm daemon socket binding check
10.VirtIO RNG entropy device allocation
11.i6300esb watchdog timer initialization
12.Pacemaker HA quorum safety verification
13.SBD fencing disk lock state check
14.Outbound mTLS certificate validity check
15.Storage pool block allocation headroom
16.MAC address duplicate check in bridge arp table
Solutions

Where enterprise teams start

Whether you're modernizing from VMware, running SAP, or building dev/test pipelines — VirtStack adapts to your workloads.

VMware Modernization

A disciplined Assess → Plan → Migrate → Validate → Operate → Optimize path, with rollback built in at every stage using virt-v2v.

Learn more

SAP on SUSE KVM

Two HA layers in one view: Pacemaker restarts general-purpose VMs; HANA System Replication protects the database. NUMA guardrails throughout.

Learn more

Dev / Test Environments

Templates and instant linked clones deliver environments in seconds with near-zero additional storage — consistent builds every time.

Learn more

Data-Centre & MSPs

Many KVM clusters and NATed customer sites, one console. Manage diverse estates centrally without opening a single inbound firewall port.

Learn more

Open source is not zero cost.

Subscriptions, licensing, skills and migration effort are real. We build a TCO model with you instead of quoting savings percentages.

Architecture

Reference architecture & Operating Model

Build once with YaST & crmsh. Operate every day from the VirtStack web console.

SUSE KVM Cluster & Pacemaker Live Control

Real-time Pacemaker/Corosync Quorum: 3 Nodes Online (Quorate) · Zero Central Root Secrets

kvm-01.sles.internalAGENT ONLINE
Operating System:

SUSE Linux Enterprise Server 15 SP7

CPU & Topology:

64 Sockets (2x Intel Xeon Platinum 8480+)

NUMA Topology Mapping:

Node 0: Cores 0-31 | Node 1: Cores 32-63

SBD Fencing & Quorum:

Fencing ready (/dev/disk/by-id/sbd-san-vol0)

Agent Management Tunnel:

Connected (Outbound mTLS Tunnel active)

Active libvirt Domains (VMs)16-point Preflight Validated
vm-sap-hana-01SAP HANA Primary

vCPU: 32 Cores · Memory: 256GB (NUMA Node 0)

SAPHanaSR Protected
vm-app-prod-01SLES 15 SP7 App

vCPU: 8 Cores · Memory: 32GB

Pacemaker Restart
vm-win11-[#04]Windows 11 (vTPM 2.0)

vCPU: 4 Cores · Memory: 16GB

General VM
Linked Clone Topology: base.qcow2 (read-only) → overlay.qcow2
Instant Provisioning & Live Flattening
Day 0
Foundation

Platform engineering with YaST, zypper, crmsh

  • Servers, SLES + KVM, networks
  • Storage, Pacemaker, Corosync, SBD
  • Built once with standard SUSE tooling
Day 1
Onboarding

VirtStack-assisted onboarding

  • One-line host enrollment
  • Hardware & NUMA discovery
  • Golden templates, adopt existing VMs
Day 2
Operations

VirtStack's core Day-2 focus

  • VM lifecycle, console, snapshots
  • NUMA placement, HA visibility
  • Live metrics, maintenance, audit trail
Zero-Trust Architecture

Designed so the server holds zero root secrets

Most virtualization managers become the single most valuable target on the network: one server holding root credentials to every hypervisor. VirtStack is designed so that server holds none.

1. No central host credentials

No root passwords, SSH private keys or libvirt TCP credentials stored on the control plane. Each agent authenticates with its own certificate issued at enrollment. Revoking a host revokes only that host’s certificate.

2. Outbound-only hypervisors

Agents open an outbound TLS connection; no inbound listener is required on hosts. Works behind NAT and egress-only firewalls, reducing lateral-movement exposure.

3. Mutual TLS everywhere

Agent ↔ control plane traffic is mutually authenticated and encrypted. Control commands, events, metrics and console streams share the same tunnel.

4. Consoles never exposed

VNC/SPICE listeners are bound to 127.0.0.1 on each host. Console access is relayed through the authenticated tunnel and control plane session.

5. Signed enrollment tokens

Enrollment tokens are cryptographically signed, single-use and expire automatically after an admin-configured validity period.

6. Immutable audit log

Every administrative action is recorded with actor, target, parameters, result and timestamp in an append-only log.

Supporting Your Enterprise Compliance Programme

FrameworkHow VirtStack Supports It
ISO/IEC 27001Append-only audit trail; encrypted management plane; no shared host credentials.
SOC 2 Type IIAutomated operational logs; mutual TLS on all communications; least-privilege service design.
DORA / NIS 2 (EU)Resilient multi-cluster architecture; no central point of cryptographic failure; fast recovery pathways.
PCI-DSS v4.0Hypervisor consoles bound to 127.0.0.1; zero external listeners on virtualization hosts.
Frequently Asked Questions

Questions about VirtStack & SLES KVM

Straightforward technical answers to the most common architectural and commercial questions.

The virtualization market shift — including new licensing and packaging models following Broadcom's acquisition of VMware in November 2023 — is turning renewals into architecture decisions. KVM has been in the mainline Linux kernel since 2007 and is supported by SUSE on SLES.
Evaluation & Demo

Try VirtStack on your own hardware

Enroll your first SUSE Linux Enterprise KVM host in minutes. 60-day full license, 4 sockets included.

Free evaluation

Hands-on Engineers

60-day licence, up to 4 sockets, full installation documentation.

Request trial →
Guided demo

Architects & Teams

45-minute live session with an engineer tailored to your use case.

Book a demo →
Talk to sales

CTOs & Procurement

Pricing, procurement, SUSE subscription bundling and custom SLAs.

Contact sales →

Request a Trial or Guided Demo

Try VirtStack on your own hardware or schedule a 45-minute live engineering walkthrough.

Ready for SLES 15 SP7 KVM?

60-day evaluation • 4 sockets included