Server Management (Unmanaged)

An In-Depth Guide to Implementing Kernel-based Virtual Machine (KVM) on Linux

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

KVM (Kernel-based Virtual Machine) turns a Linux server into a hypervisor, so one physical machine can run many isolated virtual machines. This guide sets up KVM with libvirt on a current Ubuntu LTS server, creates a VM, and covers the everyday jobs: networking, storage, snapshots and clean-up. It is for your own server, where you have root access and hardware virtualization; it cannot be done on shared hosting.

Key takeaways

Check the CPU supports virtualization (kvm-ok), install qemu-kvm, libvirt-daemon-system and virtinst, and add your user to the libvirt group. Create VMs with virt-install, manage them with virsh, and use libvirt's default NAT network unless the VMs need their own public IPs, in which case build a bridge with netplan. KVM needs a physical server or a VPS with nested virtualization; on a Domain India VPS, ask support before you try.

1. What KVM is and how it works

KVM is a set of Linux kernel modules: kvm plus kvm_intel or kvm_amd, depending on the processor. They let the kernel use the CPU's hardware virtualization features (Intel VT-x or AMD-V) to run guest operating systems directly on the processor.

Three pieces work together:

ComponentWhat it does
KVM kernel modulesUse the CPU's virtualization features; each VM runs as a normal Linux process
QEMUEmulates the VM's devices (disk, network card, display) and uses KVM for speed
libvirtA daemon and API that manages VMs, networks and storage; virsh, virt-install and Virt-Manager all talk to it

Because each VM is a Linux process, the host's scheduler, memory management, cgroups, firewall and SELinux or AppArmor all apply to it. KVM is used by most large cloud platforms and by Proxmox VE, and it is the virtualization behind Domain India VPS plans.

2. Requirements

  • A 64-bit x86 server with hardware virtualization enabled in the BIOS or UEFI (Intel VT-x or AMD-V).
  • A current Linux distribution. This guide uses Ubuntu 24.04 LTS. On AlmaLinux or Rocky Linux the packages are qemu-kvm, libvirt and virt-install, installed with dnf.
  • Enough RAM and disk for the host plus every VM you plan to run. Leave at least 1 to 2 GB of RAM for the host itself.
  • Root or sudo access. On shared hosting, you cannot load kernel modules or run a hypervisor.

Check the CPU:

bash
grep -Ec '(vmx|svm)' /proc/cpuinfo    # more than 0 means the CPU supports it
sudo apt install -y cpu-checker
kvm-ok                                # should say "KVM acceleration can be used"

If kvm-ok says virtualization is disabled, turn it on in the firmware. If you are inside a VM already, the host must offer nested virtualization.

3. Install KVM and libvirt

bash
sudo apt update
sudo apt install -y qemu-kvm libvirt-daemon-system libvirt-clients virtinst
sudo usermod -aG libvirt,kvm "$USER"

Log out and back in so the group change applies. Then verify:

bash
lsmod | grep kvm                  # kvm_intel or kvm_amd plus kvm
sudo systemctl is-active libvirtd # active
sudo virsh list --all             # empty list, no error

virtinst provides virt-install. You no longer need bridge-utils: bridges are created with netplan or the ip command, and brctl is deprecated.

4. Create your first VM

The quickest reliable way is to boot a cloud image with cloud-init, which gives you a ready server with your SSH key in a minute. Download the current Ubuntu LTS cloud image once:

bash
cd /var/lib/libvirt/images
sudo wget https://cloud-images.ubuntu.com/noble/current/noble-server-cloudimg-amd64.img

Create a VM with 2 GB of RAM, 2 vCPUs and a 20 GB disk layered on that image:

bash
sudo virt-install \
  --name web1 \
  --memory 2048 --vcpus 2 \
  --osinfo ubuntu24.04 \
  --disk size=20,backing_store=/var/lib/libvirt/images/noble-server-cloudimg-amd64.img \
  --cloud-init ssh-key="$HOME/.ssh/id_ed25519.pub" \
  --network network=default \
  --graphics none --import --noautoconsole

Find its address and log in:

bash
sudo virsh domifaddr web1
ssh [email protected]

To install from an ISO instead, replace the --disk, --cloud-init and --import lines with --disk size=20 --cdrom /var/lib/libvirt/images/installer.iso and connect to the installer with Virt-Manager or a VNC viewer. Run virt-install --osinfo list to see the operating system names your version knows.

Old guides use removed options

The --os-type option was removed from virt-install, and Ubuntu's old network-installer URLs no longer exist. Use --osinfo and a cloud image or ISO, as above.

5. Manage VMs with virsh

Run these with sudo, or as a member of the libvirt group with -c qemu:///system added, so virsh talks to the system VMs rather than an empty per-user session.

TaskCommand
List all VMsvirsh list --all
Start / graceful shutdownvirsh start web1 / virsh shutdown web1
Force power-offvirsh destroy web1
Start at host bootvirsh autostart web1
Serial console (exit with Ctrl+])virsh console web1
Change memory (while off)virsh setmaxmem web1 4G --config then virsh setmem web1 4G --config
Delete VM and its disksvirsh undefine web1 --remove-all-storage

virsh destroy does not delete anything; it only pulls the virtual power cord. virsh undefine without --remove-all-storage removes the VM definition but leaves its disk files.

If you prefer a graphical tool, install virt-manager on your desktop and connect to the server over SSH (qemu+ssh://user@server/system).

6. Networking: NAT or a bridge

libvirt creates a default NAT network (virbr0, 192.168.122.0/24). VMs can reach the internet, but the outside world cannot reach them unless you forward ports. That is fine for development and for VMs behind a reverse proxy on the host.

If VMs need their own addresses on your network, create a bridge. On Ubuntu, edit the netplan file (for example /etc/netplan/50-cloud-init.yaml; your file name may differ) and move the address from the physical interface to br0:

yaml
network:
  version: 2
  renderer: networkd
  ethernets:
    enp1s0:
      dhcp4: false
  bridges:
    br0:
      interfaces: [enp1s0]
      dhcp4: true

Replace enp1s0 with your interface name (ip link). Apply it with sudo netplan try, which rolls back automatically if you lose connection, then sudo netplan apply. Attach VMs with --network bridge=br0.

Bridging a remote server can lock you out

On a rented server you manage over SSH, a mistake in the bridge config cuts your connection. Use netplan try, keep out-of-band console access ready, and check with your provider how extra IPs must be routed: many data centres only accept traffic from registered MAC addresses, so a routed setup may be needed instead of a plain bridge.

7. Storage pools, volumes and snapshots

libvirt stores disks in storage pools; each disk is a volume. The default pool is /var/lib/libvirt/images. To add a pool on another disk:

bash
sudo virsh pool-define-as data dir --target /srv/vm-data
sudo virsh pool-build data
sudo virsh pool-start data
sudo virsh pool-autostart data

Create a 10 GB qcow2 volume and attach it to a VM as a second disk:

bash
sudo virsh vol-create-as data web1-data.qcow2 10G --format qcow2
sudo virsh attach-disk web1 /srv/vm-data/web1-data.qcow2 vdb \
  --driver qemu --subdriver qcow2 --persistent

Inside the VM, format and mount /dev/vdb as normal.

Snapshots of qcow2 disks are one command:

bash
sudo virsh snapshot-create-as web1 before-upgrade
sudo virsh snapshot-list web1
sudo virsh snapshot-revert web1 before-upgrade

A snapshot lives on the same disk as the VM, so it is not a backup. Copy disk images, or back up from inside the VM, to separate storage.

8. Performance and security basics

  • Use virtio devices for disk and network; virt-install does this by default for modern guests.
  • Do not overcommit memory heavily; a host that runs out of RAM kills VMs.
  • Keep the host minimal: no other services on it, SSH with keys only, a firewall, and regular updates.

9. Running this on Domain India

KVM needs a server you control with hardware virtualization:

  • A bare-metal server. Domain India's dedicated servers are physical machines with no virtualization layer, and the live page lists IPMI console access, which helps when you configure a bridge remotely. You run and maintain the hypervisor yourself.
  • A Domain India VPS. Our VPS plans are themselves KVM virtual machines, self-managed with full root access. The live page confirms Docker, Kubernetes and LXC containers work. Running KVM inside a VPS needs nested virtualization, which we have not documented; run kvm-ok on the VPS, and ask support before you plan around it.

If you only need isolated apps rather than whole operating systems, containers on a VPS are lighter than nested VMs.

VPS Basic
₹1,105.30/mo + GST
  • 2 vCPU
  • 4 GB DDR4 RAM
  • 128 GB NVMe SSD Storage
  • 3 TB Monthly Bandwidth
See plan details
Is KVM a type-1 or type-2 hypervisor?

KVM is built into the Linux kernel, so the host kernel itself acts as the hypervisor, which is why it is usually described as type-1. Each virtual machine runs as a normal Linux process managed by that kernel.

How do I check whether my server supports KVM?

Run grep -Ec '(vmx|svm)' /proc/cpuinfo; a result above 0 means the CPU supports it. On Ubuntu, install cpu-checker and run kvm-ok, which also tells you whether virtualization is enabled in the firmware.

Can I run KVM on shared hosting?

No. KVM needs root access, kernel modules and hardware virtualization, which shared hosting accounts do not have. You need a dedicated server, your own hardware, or a VPS that offers nested virtualization.

Can I run KVM virtual machines inside a Domain India VPS?

Domain India VPS plans are KVM virtual machines, so running KVM inside one needs nested virtualization. That is not documented; run kvm-ok on the VPS and ask Domain India support before relying on it. Docker, Kubernetes and LXC containers do work on the VPS plans.

What is the difference between virsh shutdown and virsh destroy?

virsh shutdown asks the guest operating system to shut down cleanly. virsh destroy forces the VM off immediately, like pulling the power cord; it does not delete the VM or its disks.

Do I still need bridge-utils for KVM networking?

No. The brctl tool from bridge-utils is deprecated. Create bridges with netplan on Ubuntu, NetworkManager on RHEL-based systems, or the ip command.

Is a KVM snapshot a backup?

No. An internal qcow2 snapshot is stored on the same disk as the VM, so a failed disk loses both. Keep backups on separate storage.

Ready to build your own virtualization host? Compare dedicated servers and VPS plans, or open a ticket to ask about nested virtualization before you buy.

Planning a KVM host?

Tell us how many virtual machines you want to run and what they need, and we will help you pick between a dedicated server and a VPS.

Ask our team

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app