Security & Zero-Trust Governance

Designed so the server holds zero root secrets

Most virtualization managers become the single most valuable target on the network: one server holding the root credentials to every hypervisor. VirtStack is designed so that server holds none.

Security model

1. No central host credentials

No root passwords, SSH private keys or libvirt TCP credentials stored on the control plane. Each agent authenticates with its own certificate issued at enrollment. Revoking a host revokes only that host's certificate.

2. Outbound-only hypervisors

Agents open an outbound TLS connection; no inbound listener is required on hosts. Works behind NAT and egress-only firewalls, reducing lateral-movement exposure.

3. Mutual TLS everywhere

Agent ↔ control plane traffic is mutually authenticated and encrypted. Control commands, events, metrics and console streams share the same tunnel.

4. Consoles never exposed

VNC/SPICE listeners are bound to 127.0.0.1 on each host. Console access is relayed through the authenticated tunnel and control plane session.

5. Signed enrollment

Enrollment tokens are cryptographically signed, single-use and expire automatically.

6. Immutable audit log

Every administrative action is recorded with actor, target, parameters, result and timestamp in an append-only log.

Available today vs roadmap

Security ControlStatus
mTLS agent tunnel✓ Available
No central host secrets✓ Available
Loopback-only consoles (127.0.0.1)✓ Available
Signed enrollment tokens✓ Available
Immutable audit log✓ Available
HA preflight guardrails✓ Available
Role-based access control (Platform Admin, VM Operator, Auditor)Roadmap — Phase 11
SSO via OIDC and SAML 2.0 (Okta, Keycloak, Entra ID)Roadmap — Phase 11
MFA: TOTP, FIDO2/WebAuthnRoadmap — Phase 11
SIEM log streaming (Splunk, Datadog, Elastic)Roadmap — Phase 11

Supporting your compliance programme

FrameworkHow VirtStack helps
ISO/IEC 27001Audit trail of admin actions; encrypted management plane; no shared host credentials
SOC 2Change evidence via audit log; HA visibility and fencing readiness
CERT-In directions (India)Retainable logs of administrative activity; time-stamped events
India DPDP Act, 2023On-premise and air-gapped deployment keeps workload data within your infrastructure
PCI DSSNo inbound ports on hypervisors; console traffic confined to authenticated tunnel

Responsible Disclosure

Report security concerns or vulnerabilities directly to our security engineering team at security@evomind.in.

Ready for SLES 15 SP7 KVM?

60-day evaluation • 4 sockets included