LINUX VIRTUALIZATION

Linux KVM, QEMU and libvirt Virtualization Playbook

Turn Linux into a VM host and understand the components rather than treating KVM as one monolithic application.

Servers textbookChapter 12

Learning objectives

  • Explain the main purpose of Linux KVM, QEMU and libvirt Virtualization in plain language.
  • Trace CPU, memory, network and storage from a VM through the hypervisor to physical hardware.
  • Use evidence to separate a design problem from a configuration or physical fault.
  • Describe the business impact of a failure and the evidence required for handover.

Why this matters in a real company

Virtualization lets a company run several independent server workloads on fewer physical machines. The benefit is flexibility and easier recovery, but one badly designed host can also become a large single point of failure.

Course: Servers and Virtualization Technical Textbook

PLAIN ENGLISH

Technical terms used in this chapter

You do not need to memorise the jargon first. Understand what each term does and why somebody running a company would care about it.

libvirt

libvirt

A management layer and API for virtual machines and hypervisors such as KVM/QEMU.

In everyday business: Tools can manage VMs consistently instead of controlling each process manually.

Volume

Container Volume

Persistent storage kept separately from the short-lived container filesystem.

In everyday business: Company data can survive when an application container is replaced.

Image

Container Image

A read-only package containing an application and its required files used to create containers.

In everyday business: IT can deploy the same known application build repeatedly.

vCPU

Virtual CPU

A virtual processor assigned to a VM and scheduled onto the host's physical CPU resources.

In everyday business: It is how a VM gets computing time without owning a physical processor.

QEMU

QEMU

Software that provides virtual hardware and runs guest VM processes, commonly used with KVM.

In everyday business: It supplies the virtual devices a guest operating system expects.

NAT

Network Address Translation

A router or firewall function that changes IP addressing as traffic crosses a boundary.

In everyday business: Many private office devices can share one public Internet address.

KVM

Kernel-based Virtual Machine

Linux kernel virtualization technology that turns Linux into a hypervisor.

In everyday business: A Linux server can run Windows and Linux virtual machines.

MPO

Multi-fibre Push-On

A multi-fibre optical connector used in high-density and parallel-optics systems.

In everyday business: Many fibre strands can be connected in one compact interface.

See the complete plain-English glossary

BUSINESS TRANSLATION

What this means outside the server room

This topic affects the systems staff depend on for sign-in, files, applications and business continuity. The technical design determines how easy the environment is to manage and how painful a failure becomes.

VLAN

What it means: A VLAN creates a separate logical network even when devices share the same physical switches.

In normal business language: Think of one office building with separate departments using the same corridors but different access-controlled areas. Staff, cameras, voice and guests can share the same switching hardware without all being in one open network.

Why the decision matters: Use VLANs to separate traffic for security, performance and easier troubleshooting without buying a separate physical switch for every department.

Hypervisor

What it means: A hypervisor lets one physical server run several isolated virtual machines.

In normal business language: Think of one office building divided into secure independent suites. The building is shared, but each tenant operates separately.

Why the decision matters: Virtualization reduces hardware sprawl and improves flexibility, but the physical host becomes important because several business systems can depend on it.

Virtual Machine

What it means: A virtual machine is a software-defined computer with its own operating system, memory, CPU allocation, disks and network interfaces.

In normal business language: It behaves like a separate server even though several VMs may share one physical machine.

Why the decision matters: VMs are useful for separating roles such as domain control, file sharing and applications while keeping management and recovery flexible.

Firewall

What it means: A firewall controls which network connections are allowed between users, systems and external networks.

In normal business language: It is a security checkpoint between parts of the company network. It should allow legitimate work while blocking unwanted access.

Why the decision matters: Firewall rules should describe real business flows such as 'staff may reach accounting on HTTPS', not unexplained broad permits.

NAT

What it means: NAT changes IP addresses as traffic crosses a network boundary.

In normal business language: It is similar to a company switchboard: many internal extensions can share one public number.

Why the decision matters: NAT helps with address use and publishing services, but it is not a substitute for firewall security.

Container

What it means: A container packages an application and its dependencies while sharing the host operating-system kernel.

In normal business language: Think of standardised shipping containers: the application is packaged the same way even when moved between compatible systems.

Why the decision matters: Containers improve deployment consistency, but persistent data, networking, security and backup still need deliberate design.

Linux KVM software stack
virsh / virt-install / Cockpit / APIlibvirtQEMU VM ProcessesLinux Kernel + KVM

The stack

Red Hat documents RHEL virtualisation as KVM in the kernel, QEMU in user space and libvirt as the management layer.

RHEL 10 packages

dnf install qemu-kvm libvirt virt-install virt-viewer

Create a lab VM

virt-install   --name lab01   --memory 4096   --vcpus 2   --disk size=60   --network network=default   --cdrom /var/lib/libvirt/images/install.iso

virsh basics

virsh list --all
virsh start lab01
virsh shutdown lab01
virsh dominfo lab01
virsh net-list --all
virsh pool-list --all

Networking

The default libvirt NAT network is useful for labs. Production VMs that need direct LAN presence commonly use a Linux bridge or equivalent connected to a physical NIC.

Storage

VM disks can use qcow2/raw files, logical volumes or other supported backends. Thin provisioning needs capacity monitoring because the host can run out of physical space while guests still report free space.

PRACTICAL WORK

Hands-on lab

Create one small lab VM, connect it to the intended virtual network, install an OS, record its vCPU, RAM and disk allocation, and prove network and storage paths.

Troubleshooting exercise

A VM is running but cannot reach the LAN. Check guest IP, guest firewall, vNIC, virtual switch or bridge, VLAN, host uplink and physical switch in that sequence.

Chapter field checklist

  • I can explain the subject without relying only on acronyms.
  • I can draw or describe the main traffic, storage, power or service path.
  • I know what normal operation should look like.
  • I know which logs, counters or test results prove the result.
  • I can explain the business impact if this component fails.
  • I would document the final configuration and evidence at handover.

Chapter summary

Linux KVM, QEMU and libvirt Virtualization Playbook should now be understood as a business service with a technical implementation, not simply a collection of commands or product names. The important habit is to know the purpose, understand the dependencies, measure the result and document what was proven.