Thursday, September 24, 2026

State-Isolated KVM Hypervisor Architecture on openSUSE Tumbleweed bare metal case (Assisted by Google AI)

Advantages of the YaST Installer
Extreme Customization During Setup: Unlike many rigid Linux installers that force you to accept default software or partitioning, YaST lets you modify virtually every parameter - including  complicated BTRFS/XFS disk layout, provides builtin interface for additional subvolumes decouple if it appears to be required, adding or removing specific software packages, desktop environments, and multimedia codecs before the installation even begins.

Centralized System Control: It acts as a single, unified control center for hardware configuration, partitioning, bootloader options, user accounts, and network setups. Reduced Need for CLI Knowledge: It bridges the gap for users who prefer a graphical interface (GUI) or text-based menu (ncurses) over manually editing low-level configuration files in the terminal.
YaST stands for Yet another Setup Tool, and it functions as both the primary operating system installer and the central system
configuration utility for SUSE Linux distributions 

******************
Final disk layout
******************
localhost:~ # hostnamectl
Transient hostname: localhost
   Static hostname: (unset)
         Icon name: computer-desktop
           Chassis: desktop 🖥
 Chassis Asset Tag: To be filled by O.E.M.
        Machine ID: 90c6a130b51143a285a54496a71901d8
           Boot ID: 5cefbc13c5004fe39cc1edf4a2422e05
      Product UUID: af95be8a-eace-8515-aaa1-00d861d9318b
  Operating System: openSUSE Tumbleweed
       CPE OS Name: cpe:2.3:o:opensuse:tumbleweed:20260922:*:*:*:*:*:*:*
            Kernel: Linux 7.2.6-1-default
      Architecture: x86-64
   Hardware Vendor: Micro-Star International Co., Ltd.
    Hardware Model: MS-7C37
   Hardware Serial: To be filled by O.E.M.
  Hardware Version: 3.0
  Firmware Version: H.60
     Firmware Date: Wed 2019-11-06
      Firmware Age: 6y 10month 2w 4d


localhost:~ # findmnt -t btrfs
TARGET              SOURCE                                    FSTYPE OPTIONS
/                   /dev/nvme1n1p4[/@/.snapshots/19/snapshot] btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=283,subvol=/@/.snapshots/19/snapshot
├─/.snapshots       /dev/nvme1n1p4[/@/.snapshots]             btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=263,subvol=/@/.snapshots
├─/etc/libvirt/qemu /dev/nvme1n1p4[/@/etc/libvirt/qemu]       btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=257,subvol=/@/etc/libvirt/qemu
├─/root             /dev/nvme1n1p4[/@/root]                   btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=261,subvol=/@/root
├─/home             /dev/nvme1n1p4[/@/home]                   btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=262,subvol=/@/home
├─/srv              /dev/nvme1n1p4[/@/srv]                    btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=260,subvol=/@/srv
├─/usr/local        /dev/nvme1n1p4[/@/usr/local]              btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=259,subvol=/@/usr/local
└─/var              /dev/nvme1n1p4[/@/var]                    btrfs  rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=258,subvol=/@/var

localhost:~ # df -Th
Filesystem     Type      Size  Used Avail Use% Mounted on
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /
devtmpfs       devtmpfs   16G     0   16G   0% /dev
tmpfs          tmpfs      16G     0   16G   0% /dev/shm
efivarfs       efivarfs  128K   28K   96K  23% /sys/firmware/efi/efivars
tmpfs          tmpfs     6.3G  1.9M  6.3G   1% /run
tmpfs          tmpfs      16G   20K   16G   1% /tmp
none           tmpfs     1.0M     0  1.0M   0% /run/credentials/systemd-journald.service
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /.snapshots
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /etc/libvirt/qemu
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /root
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /home
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /srv
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /usr/local
/dev/nvme1n1p4 btrfs     291G   14G  276G   5% /var
/dev/nvme1n1p2 ext4      2.0G  105M  1.7G   6% /boot
/dev/nvme1n1p3 xfs       185G   16G  169G   9% /opt
/dev/nvme1n1p1 vfat      511M  281M  231M  55% /boot/efi
tmpfs          tmpfs     3.2G   72K  3.2G   1% /run/user/1000
none           tmpfs     1.0M     0  1.0M   0% /run/credentials/getty@tty1.service


********************************************************
Decouple of @/etc/libvirt/qemu was performed during
YaST Installer partition phase
**********************************************************
Suse Tumbleweed  redefining location of libvirt default pool
**********************************************************
# 1. Stop the modular QEMU daemon and its active socket
sudo systemctl stop virtqemud.service virtqemud.socket
sudo mkdir -p /opt/libvirt/images

# 2. Migrate existing images (if you have any)
if [ -d /var/lib/libvirt/images ] && [ "$(ls -A /var/lib/libvirt/images 2>/dev/null)" ]; then
   sudo mv /var/lib/libvirt/images/* /opt/libvirt/images/
fi

# 3. Configure folder permissions and SELinux contexts for Tumbleweed
sudo chown root:root /opt/libvirt/images
sudo chmod 0711 /opt/libvirt/images
sudo semanage fcontext -a -t virt_image_t "/opt/libvirt/images(/.*)?"
sudo restorecon -R -v /opt/libvirt/images

# 4. Restart the modular service/socket and reassign the default pool via virsh
sudo systemctl start virtqemud.socket virtqemud.service
sudo virsh pool-destroy default 2>/dev/null
sudo virsh pool-undefine default 2>/dev/null
sudo virsh pool-define-as default dir --target "/opt/libvirt/images"
sudo virsh pool-start default
sudo virsh pool-autostart default

# 5. Verify the configuration
sudo virsh pool-dumpxml default | grep path


**********************
Proof of concept
**********************
localhost:~ # df -Th /opt/libvirt/images
Filesystem     Type  Size  Used Avail Use% Mounted on
/dev/nvme0n1p3 xfs   185G  7.8G  177G   5% /opt

localhost:~ # ls -Zl /opt/libvirt/images
total 4394808
-rw-------. 1 qemu qemu system_u:object_r:svirt_image_t:s0:c421,c703 32217432064 Sep 24 07:22 ArchCosmic0924.qcow2
localhost:~ # ls -Zl /etc/libvirt/qemu
total 8
-rw-------. 1 root root system_u:object_r:virt_etc_rw_t:s0 8118 Sep 24 06:54 ArchCosmic0924.xml
drwx------. 1 root root system_u:object_r:virt_etc_rw_t:s0    0 Sep 16 17:09 autostart
drwx------. 1 root root system_u:object_r:virt_etc_rw_t:s0   40 Sep 24 06:17 networks  

***********************

Snapshot tracking                                    

***********************
localhost:~ # snapper -c root list |tail -5
 8  │ post   │     5 │ Thu 24 Sep 2026 06:10:49 AM EDT │ root │ 352.00 KiB │ number  │                           │
 9  │ pre    │       │ Thu 24 Sep 2026 06:22:47 AM EDT │ root │  28.00 MiB │ number  │ zypp(zypper)              │ important=no
10  │ post   │     9 │ Thu 24 Sep 2026 06:22:59 AM EDT │ root │  15.80 MiB │ number  │                           │ important=no
11  │ single │       │ Thu 24 Sep 2026 06:49:14 AM EDT │ root │  16.00 KiB │         │ KVM Setup.No vms deployed │
12  │ single │       │ Thu 24 Sep 2026 06:50:26 AM EDT │ root │  16.00 KiB │         │ KVM Setup. Arch ISO extracted    

ArchCosmic0924 deployed as L1 Guest.

localhost:~ # snapper rollback 12
Ambit is classic.
Creating read-only snapshot of current system. (Snapshot 13.)
Creating read-write snapshot of snapshot 12. (Snapshot 14.)
Setting default subvolume to snapshot 14.

System rebooted into /@/.snapshots/14/snapshot

boris@localhost:~> sudo su -
[sudo] password for root:
localhost:~ # mount | grep 'on / '
/dev/nvme1n1p4 on / type btrfs (rw,relatime,seclabel,ssd,discard=async,space_cache=v2,subvolid=278,subvol=/@/.snapshots/14/snapshot)

localhost:~ # virsh list --all
 Id   Name             State
--------------------------------
 1    ArchCosmic0924   running




















Thursday, September 17, 2026

State-Isolated KVM Hypervisor Architecture for Sparky 2026 06 (Assisted by Google AI)

 This architectural review validates a methodology for structural state-decoupling on a Linux hypervisor host. Traditional unified storage typologies expose nested. By designing a hybrid layout that maps the host operating system to a Timeshift-tracked Btrfs subvolume tree while binding guest runtime files to an independent, non-Copy-on-Write (No-CoW) enterprise XFS partition, we establish complete rollback immunity.
This review confirms that reverting the host root Timeshift snapshots leaves nested guest XML definitions and high-allocation QCOW2 volumes completely undisturbed and operationally continuous.


******************************************
Final Disk layout of Sparky 2026 06 instance
******************************************
root@devs-SW8664:~# uname -a
Linux devs-SW8664 7.1.13+deb14-amd64 #1 SMP PREEMPT_DYNAMIC Debian 7.1.13-1 (2026-09-03) x86_64 GNU/Linux

*************************************************************
Folder /opt was created during Calamares setup and formated as XFS.
**************************************************************
root@devs-SW8664:~# df -Th
Filesystem     Type      Size  Used Avail Use% Mounted on
/dev/vda3      btrfs      51G  7.6G   42G  16% /
devtmpfs       devtmpfs  7.6G     0  7.6G   0% /dev
tmpfs          tmpfs     7.6G  4.5M  7.6G   1% /dev/shm
efivarfs       efivarfs  256K   97K  154K  39% /sys/firmware/efi/efivars
tmpfs          tmpfs     3.1G  1.1M  3.1G   1% /run
none           tmpfs     1.0M     0  1.0M   0% /run/credentials/systemd-journald.service
tmpfs          tmpfs     7.6G  8.0K  7.6G   1% /tmp
/dev/vda3      btrfs      51G  7.6G   42G  16% /home
/dev/vda3      btrfs      51G  7.6G   42G  16% /var/log
/dev/vda3      btrfs      51G  7.6G   42G  16% /var/cache
/dev/vda3      btrfs      51G  7.6G   42G  16% /etc/libvirt/qemu
/dev/vda2      ext4      2.0G  182M  1.7G  10% /boot
/dev/vda4      xfs        44G  5.4G   39G  13% /opt
/dev/vda1      vfat      300M   15M  286M   5% /boot/efi
tmpfs          tmpfs     1.6G  120K  1.6G   1% /run/user/1000

**************************************************************
Resulting btrfs flat layout after decoupling subvolume @qemu
**************************************************************
root@devs-SW8664:~# findmnt -t btrfs
TARGET         SOURCE             FSTYPE OPTIONS
/              /dev/vda3[/@]      btrfs  rw,relatime,compress=zstd:1,discard=async,space_cache=v2,subvolid=297,subvol=/@
├─/home        /dev/vda3[/@home]  btrfs  rw,relatime,compress=zstd:1,discard=async,space_cache=v2,subvolid=296,subvol=/@home
├─/etc/libvirt/qemu
│              /dev/vda3[/@qemu]  btrfs  rw,relatime,compress=zstd:1,discard=async,space_cache=v2,subvolid=283,subvol=/@qemu

├─/var/log     /dev/vda3[/@log]   btrfs  rw,relatime,compress=zstd:1,discard=async,space_cache=v2,subvolid=259,subvol=/@log
└─/var/cache   /dev/vda3[/@cache] btrfs  rw,relatime,compress=zstd:1,discard=async,space_cache=v2,subvolid=258,subvol=/@cache
**********************************************************
 Final status of default libvirt-pool after switching from /var/lib/libvirt/images to 
/opt/libvirt/images
**********************************************************

root@devs-SW8664:~# virsh pool-info default
Name:           default
UUID:           0a07f1dd-e6c6-4f0a-8fae-808662b9c7ab
State:          running
Persistent:     yes
Autostart:      yes
Capacity:       43.88 GiB
Allocation:     5.33 GiB
Available:      38.55 GiB

root@devs-SW8664:~# virsh pool-dumpxml default | grep path
   <path>/opt/libvirt/images</path>

*************************
Phase 1
*************************
Follows exactly Sparky Linux 2026 06 OverlayFS BTRFS with Timeshift setup

 ************************
Post installation Phase 2
************************
#1. Install KVM Hypervisor and Cockpit Web Console
#2. Decouple @qemu sub-volume mounted on /etc/libvirt/qemu


In particular case /dev/vda3 was formatted as XFS and    /dev/vda4 was formatted BTRFS


root@devs-SW8664:~# cat Setup001
# -- Step 1-2. Preparation: Create the subvolume first (assuming /mnt/btrfs-top is your top-level mount)
sudo mkdir -p /mnt/btrfs-top
sudo mount -o subvolid=5  /dev/vda4 /mnt/btrfs-top
sudo btrfs subvolume create /mnt/btrfs-top/@qemu

# --  Step 3: Sync data to a safe temporary location
sudo mkdir -p /mnt/temp-qemu
sudo mount -o subvol=@qemu /dev/vda4 /mnt/temp-qemu
sudo rsync -aHAX /etc/libvirt/qemu/ /mnt/temp-qemu/
sudo umount /mnt/temp-qemu

# -- CRITICAL SUB-STEP: Clear out the old directory contents before mounting over it
# (If you don't do this, old files remain hidden underneath, wasting space)
sudo rm -rf /etc/libvirt/qemu/*

# -- Step 4: Inject mapping (Using your actual Btrfs UUID from vda3)
echo "UUID=2f880c1f-d17c-4213-a515-0b1a78b1e6be  /etc/libvirt/qemu btrfs subvol=@qemu,defaults,compress=zstd:1 0 0" | \        sudo tee -a /etc/fstab

# -- Step 5: Reload and Mount
sudo systemctl daemon-reload
sudo mount -a

# -- Clean up the top-level mount
sudo umount /mnt/btrfs-top

#--Step 6. Apply Security and Ownership Integrity Restorations
# Ensure the new mount point maintains strict ownership for root and the libvirt group
sudo chown -R root:libvirt /etc/libvirt/qemu
sudo chmod 750 /etc/libvirt/qemu

# Reload AppArmor profiles to ensure libvirt recognizes the path changes flawlessly
sudo systemctl reload apparmor

# 6-1. Create the standard configuration subdirectories if they don't exist
sudo mkdir -p /etc/libvirt/qemu/autostart /etc/libvirt/qemu/networks

# 6-2. Reset strict ownership to root and the libvirt group
sudo chown -R root:libvirt /etc/libvirt/qemu

# 6-3. Apply secure permission bits (750 for qemu, 700 for subfolders)
sudo chmod 750 /etc/libvirt/qemu
sudo chmod 700 /etc/libvirt/qemu/autostart /etc/libvirt/qemu/networks

# 6-4. Restart libvirt to safely hook into the new subvolume
sudo systemctl restart libvirtd

*****************************************
#3. Switching to new libvirt-pool as root
*****************************************

mkdir -p /opt/libvirt/images

chown root:root /opt/libvirt/images   
chmod 0711 /opt/libvirt/images

# 1. Stop the active default pool
virsh pool-destroy default

# 2. Delete the old definition
virsh pool-undefine default

# 3. Define the new default pool path
virsh pool-define-as --name default --type dir --target /opt/libvirt/images

# 4. Start the pool and set it to autostart on boot
virsh pool-start default
virsh pool-autostart default

********************
Tuning apparmor
********************
root@devs-SVC8664:~#sudo nano /etc/apparmor.d/local/abstractions/libvirt-qemu
root@devs-SVC8664:~# cat /etc/apparmor.d/local/abstractions/libvirt-qemu
/opt/libvirt/images/** rwk,
root@devs-SVC8664:~# sudo systemctl reload apparmor