如何在命令行不使用virt-install启动带libvirt/sVirt的QEMU KVM
无virt-install依赖、基于virsh启动带sVirt防护的KVM实例操作方案
前置环境检查
- 确认基础组件已安装:宿主机需部署
libvirt、qemu-kvm组件,执行systemctl is-active libvirtd确认libvirtd服务处于运行状态。 - 确认sVirt默认开关开启:sVirt是libvirt原生集成的安全隔离机制,依赖SELinux实现,检查
/etc/libvirt/qemu.conf中配置项为security_driver = "selinux",如果修改过配置需执行systemctl restart libvirtd生效。 - 准备虚拟机磁盘:提前创建好qcow2格式的系统磁盘,优先存放在libvirt默认镜像目录
/var/lib/libvirt/images/下;如果存放在自定义路径,需提前配置SELinux文件规则避免权限报错:semanage fcontext -a -t virt_image_t "/your/custom/image/path(/.*)?" restorecon -Rv /your/custom/image/path
步骤1:编写域配置XML文件
不使用virt-install的核心是手动编写符合libvirt规范的域配置文件,sVirt所需的安全标签无需手动写入XML,libvirt会在定义实例时自动生成专属动态隔离标签。以下是最小可用配置示例,可保存为/tmp/svirt-vm.xml:
<domain type='kvm'> <name>svirt-test-vm</name> <memory unit='GiB'>2</memory> <vcpu placement='static'>2</vcpu> <os> <type arch='x86_64' machine='q35'>hvm</type> <boot dev='hd'/> </os> <features> <acpi/> <apic/> </features> <cpu mode='host-passthrough' check='none'/> <devices> <emulator>/usr/libexec/qemu-kvm</emulator> <disk type='file' device='disk'> <driver name='qemu' type='qcow2'/> <source file='/var/lib/libvirt/images/svirt-test-vm.qcow2'/> <target dev='vda' bus='virtio'/> </disk> <interface type='network'> <source network='default'/> <model type='virtio'/> </interface> <graphics type='vnc' port='-1' autoport='yes' listen='127.0.0.1'/> <console type='pty'> <target type='serial' port='0'/> </console> </devices> </domain>
步骤2:导入配置并启动实例
所有操作通过virsh完成,全程无需调用virt-install:
- 校验并注册虚拟机配置到libvirt,该步骤会自动为实例分配全局唯一的sVirt动态安全标签:
virsh define /tmp/svirt-vm.xml - 确认sVirt标签已自动生成,执行以下命令能看到
seclabel段类型为dynamic,标签值类似system_u:system_r:svirt_t:s0:c128,c456(末尾的c分类是每个实例专属,是sVirt实现跨实例隔离的核心):virsh dumpxml svirt-test-vm | grep -A 5 seclabel - 启动虚拟机实例:
virsh start svirt-test-vm
步骤3:验证sVirt隔离生效
- 检查QEMU进程安全上下文:执行
ps auxZ | grep qemu-kvm | grep svirt-test-vm,确认进程运行在专属的svirt_t带独立分类的上下文下,而非通用qemu_t上下文。 - 检查磁盘文件标签:执行
ls -Z /var/lib/libvirt/images/svirt-test-vm.qcow2,确认磁盘文件被自动打上和进程匹配的svirt_image_t标签,其他虚拟机进程无权限读写该磁盘。 - 权限校验测试:切换到其他运行中VM的sVirt上下文尝试读取该磁盘文件,会返回Permission denied,证明隔离规则生效。
注意事项
- 禁止手动编辑libvirt自动生成的seclabel配置段,会导致sVirt隔离失效或虚拟机启动失败
- 禁止绕过libvirt直接执行qemu-kvm命令启动实例,该方式不会触发sVirt标签配置,无任何sVirt安全防护
- 挂载自定义ISO、透传主机设备时,需提前配置对应资源的SELinux上下文,否则会出现权限报错
内容的提问来源于stack exchange,提问作者Deekshith Reddy
相关产品推荐
相关产品推荐

