VorticPanel

Installation

Network and storage by hand

Most people can skip this page. The install command in Adding a node sets up the bridge and storage itself. Use this page if it couldn’t, for example on Rocky or Alma Linux (NetworkManager), with a bonded network, or if you’d rather do it yourself.

Do this as root, preferably from a console (IPMI, iDRAC or your provider’s web console). A mistyped network change can cut off SSH.

The bridge

Servers plug into a Linux bridge on the public network. The bridge takes over the machine’s IP address. Call it br-public and the panel uses it without any setting; with another name, pick it under the node’s Settings → Public bridge.

Find your interface’s name, address and gateway first:

ip -br addr
ip route show default
# /etc/netplan/01-br-public.yaml, replacing the interface's own settings in the other files
network:
  version: 2
  ethernets:
    eno1:
      dhcp4: false
      dhcp6: false
  bridges:
    br-public:
      interfaces: [eno1]
      macaddress: aa:bb:cc:dd:ee:ff   # eno1's MAC, from: cat /sys/class/net/eno1/address
      addresses: [203.0.113.10/24]
      routes:
        - to: default
          via: 203.0.113.1
      nameservers: { addresses: [1.1.1.1] }
      parameters: { stp: false, forward-delay: 0 }

Apply it: on Ubuntu netplan try (it undoes the change if you don’t confirm), on Debian systemctl restart networking, or reboot.

Check: ip -br addr show br-public shows the machine’s address, and you can still reach it. Then restart the agent so the panel sees the bridge: systemctl restart panel-agent.

Customers’ private networks don’t need a bridge of their own: the agent creates a VXLAN bridge per network.

Storage

The panel registers the node’s storage itself when it first connects. To set up something else, create it, then add it on the node’s Storage tab with Add storage:

Kind Set-up Notes
LVM thin (recommended) pvcreate /dev/nvme1n1 && vgcreate vg0 /dev/nvme1n1 && lvcreate -l 90%FREE --thinpool data vg0 Fast snapshots, thin provisioning. The install command’s --storage-disk does this for you.
LVM A volume group with free space Thick volumes
ZFS An existing pool with a dataset, e.g. tank/vms Install ZFS yourself
qcow2 files Nothing to do: /var/lib/libvirt/images Fine for testing

See Storage for how pools, tiers and thin provisioning work.

Between nodes

Moving servers between nodes uses SSH between their management addresses, and customers’ private networks use VXLAN. Allow, between nodes:

Port Used for
TCP 22 Moving servers (virsh migrate over SSH as root)
UDP 4789 Private networks (VXLAN, MTU 1450)

The install command installs an SSH server; if you set the node up yourself, check sshd is running.

What private networks put on a node

Only while a server on the node is on a private network, and all made and removed by the agent:

  • A bridge and a VXLAN link per network, named pn4100 and vx4100 after the network’s segment ID. They have no IP address: the node itself isn’t on the customer’s network, and its own addresses and routes don’t change.
  • A second network card in each member server, plugged in and out while it runs. The agent sets the address inside the server through the guest agent, saved so it survives a reboot (netplan, NetworkManager, ifupdown or systemd-networkd on Linux; Windows keeps it by itself). Without a guest agent the customer gets the commands to run.
  • A firewall table, panel_vxlan, that lets UDP 4789 in only from the other nodes sharing a network with this one, so nobody else can put packets onto a customer’s network. Each server can also only send on a private network as its own card there.

When the last server on the node leaves a network (detached, deleted, moved away), its bridge, link and firewall entries go, and the other nodes stop sending to this one. After the node restarts, the agent puts the networks back and starts the servers on them that libvirt couldn’t autostart.

Private network traffic between nodes (VXLAN) isn’t encrypted: keep the management network private (a VLAN or private switch between your nodes) rather than across the internet where you can. Moves are encrypted either way; they go over SSH. If a node has its own firewall (ufw, firewalld), allow UDP 4789 from the other nodes there too.

Every word has to appear. ↑ ↓ to move, Enter to open.