Feature Reference & Roadmap

VirtStack Features & Capability Reference

VirtStack turns a fleet of SUSE Linux Enterprise Server KVM hosts into a single, secure, browser-managed platform. This page separates what is available today from what is on the committed roadmap, so you can plan with confidence.

Feature matrix

CategoryAvailable now (Shipping Today)Committed Roadmap
Fleet & host onboardingOne-line enrollment, hardware & NUMA discovery, maintenance modeRolling host updates, hardware certification suite
VM lifecycleStart / shutdown / force off / reboot / pause / resume / delete; 16 preflight checksBulk power operations, power schedules
ConsoleIn-browser noVNC over encrypted tunnel; live ISO attach/ejectSPICE audio, browser USB redirection
Virtual hardwarevCPU, RAM, disks, NICs, USB & PCI passthrough, vTPM, RNG, watchdogAutomatic balloon tuning, CPU hot-add
StoragePool discovery (dir, NFS, LVM), online volume expansion, safe external disk attachShared SDS orchestration, thin-provisioning alerts
NetworkingNAT, routed, isolated & bridged networks; multi-NIC; 4-stage IP discoveryVXLAN/Geneve overlays, distributed firewall
Snapshots & clonesDisk + RAM snapshots, full & linked clones, live flattening, identity resetScheduled snapshots with retention
PlacementTwo-stage engine, NUMA-aware pinning, decision logsDynamic balancing / DRS-style rebalancing
ObservabilityLive event stream, per-second metrics, datacenter dashboardHistorical trends, Prometheus/Grafana
High availabilityPacemaker/Corosync monitoring, SBD inspection, safe resource relocationOne-click evacuation, automated split-brain recovery
Security & governanceImmutable audit log, signed enrollment tokens, mTLS agent tunnelRBAC, OIDC/SAML SSO, MFA, Vault, multi-tenancy
MigrationMigration wizard with capacity & compatibility validationLive migration, live storage copy without shared storage

Fleet onboarding & host discovery

Benefit: A new hypervisor is manageable within minutes of OS install — no firewall tickets, no key distribution.

  • One-line enrollment using a time-bounded, cryptographically signed token.
  • Hardware inventory: sockets, cores, threads, virtualization extensions (VT-x / AMD-V), memory.
  • NUMA topology mapping of cores and memory per cell.
  • Maintenance mode cordons a host from new placements while existing VMs keep running.
  • Self-healing connection with exponential backoff after network interruptions.
Host Enrollment Agent Installer
# Illustrative — see the Quickstart for exact syntax
curl -fsSLo virtstack-agent.sh https://<control-plane>/install/agent.sh
sudo bash virtstack-agent.sh --token '<ENROLLMENT_TOKEN>'

VM lifecycle & provisioning

Benefit: Fewer failed deployments and no “it fit on paper” surprises.

Supported Lifecycle Actions

StartDomain is started via libvirt
Graceful shutdownACPI power-button event sent to guest
Force offImmediate hypervisor-level stop
Pause / ResumevCPUs suspended; memory & disks remain
DeleteDomain undefined; choose to keep or wipe disks

Provisioning Wizard & Preflight

Sockets/cores/threads, memory with ballooning limits, disk bus (virtio-blk, virtio-scsi/SCSI, SATA, IDE) and format (QCOW2, raw), network attachment, ISO and boot order.

16-point preflight gate: validates host RAM headroom, CPU overcommit thresholds, datastore capacity and bridge availability before submission.

Operator note: Pause is not a substitute for shutdown on long maintenance windows — guest clocks and remote TCP sessions may time out while paused.

16-Point Preflight Gate Interactive Simulator

VirtStack validates host headroom, CPU overcommit, datastore capacity & bridges before submitting to libvirt.

16 / 16 PASSED
Requested RAM:32 GB
Host Free: 128 GB (Max recommended)
Requested vCPUs:8 Cores
Overcommit limit: 32 Cores
Storage Capacity:100 GB
Pool Free: 500 GB
01.Host RAM headroom check (non-ballooned physical RAM available)
02.CPU overcommit ratio threshold check (<= 4:1 ratio)
03.Datastore volume storage capacity validation
04.Host network bridge interface availability (br0)
05.NUMA node alignment & vCPU pinning validation
06.libvirt domain XML schema compliance
07.QEMU binary & SLES 15 SP7 kernel capability check
08.AppArmor mandatory access control profile readiness
09.vTPM 2.0 swtpm daemon socket binding check
10.VirtIO RNG entropy device allocation
11.i6300esb watchdog timer initialization
12.Pacemaker HA quorum safety verification
13.SBD fencing disk lock state check
14.Outbound mTLS certificate validity check
15.Storage pool block allocation headroom
16.MAC address duplicate check in bridge arp table

Virtual hardware & devices

Benefit: vSphere-level hardware control, exposed through a UI rather than hand-edited domain XML.

CPU Topology & Mode

host-passthrough for maximum performance, or named CPU models (e.g. Cascadelake-Server) for migration across mixed CPU generations.

PCIe / GPU Passthrough (VFIO)

Pass physical GPUs, NVMe controllers, dedicated NICs, and USB license dongles directly to guests.

vTPM 2.0 (swtpm)

Backed by swtpm on the host; required for Windows 11 and supports BitLocker disk encryption.

RNG & Watchdogs

VirtIO RNG for entropy and i6300esb watchdogs for hung-guest automatic recovery.

Generated libvirt vTPM 2.0 Domain XML
<!-- Example of what VirtStack generates for a vTPM (for reference only) -->
<tpm model="tpm-crb">
  <backend type="emulator" version="2.0"/>
</tpm>

Snapshots, full clones & linked clones

Benefit: Stand up test and training environments in seconds, and roll back safely.

Snapshots

External disk snapshots or full memory + disk; revert to any point; delete with background block-commit to keep chains short.

Linked Clones (QCOW2)

QCOW2 overlay on a read-only base — seconds to provision, near-zero initial storage. Full backing-chain visibility.

Live Flattening & Identity

Convert a linked clone to standalone without downtime. Automatic SMBIOS UUID, MAC, and machine-id reset.

COMMITTED ROADMAP BY PHASE

Product Roadmap

Four levels of certainty. Relative phases only — no dates are committed on this page.

Phase 8 · Scheduling & Backup

Durable cron-style snapshots/backups, retention (7 daily / 4 weekly / 12 monthly), dev/test power schedules.

Phase 11 · Identity & Compliance

RBAC personas, OIDC & SAML 2.0 SSO, TOTP & FIDO2/WebAuthn MFA, multi-tenant scoping, automated mTLS cert rotation, SIEM streaming.

Phase 12 · Fleet Scaling

Horizontally scaled gateways (50+ hypervisors), automatic gateway failover.

Phase 13 · DR & Hardening

Off-site snapshot replication, active-active control plane, host certification suite.

Ready for SLES 15 SP7 KVM?

60-day evaluation • 4 sockets included