You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在命令行不使用virt-install启动带libvirt/sVirt的QEMU KVM

无virt-install依赖、基于virsh启动带sVirt防护的KVM实例操作方案

前置环境检查

  • 确认基础组件已安装:宿主机需部署libvirt、qemu-kvm组件,执行systemctl is-active libvirtd确认libvirtd服务处于运行状态。
  • 确认sVirt默认开关开启:sVirt是libvirt原生集成的安全隔离机制,依赖SELinux实现,检查/etc/libvirt/qemu.conf中配置项为security_driver = "selinux",如果修改过配置需执行systemctl restart libvirtd生效。
  • 准备虚拟机磁盘:提前创建好qcow2格式的系统磁盘,优先存放在libvirt默认镜像目录/var/lib/libvirt/images/下;如果存放在自定义路径,需提前配置SELinux文件规则避免权限报错:
    semanage fcontext -a -t virt_image_t "/your/custom/image/path(/.*)?"
    restorecon -Rv /your/custom/image/path
    

步骤1:编写域配置XML文件

不使用virt-install的核心是手动编写符合libvirt规范的域配置文件,sVirt所需的安全标签无需手动写入XML,libvirt会在定义实例时自动生成专属动态隔离标签。以下是最小可用配置示例,可保存为/tmp/svirt-vm.xml:

<domain type='kvm'>
  <name>svirt-test-vm</name>
  <memory unit='GiB'>2</memory>
  <vcpu placement='static'>2</vcpu>
  <os>
    <type arch='x86_64' machine='q35'>hvm</type>
    <boot dev='hd'/>
  </os>
  <features>
    <acpi/>
    <apic/>
  </features>
  <cpu mode='host-passthrough' check='none'/>
  <devices>
    <emulator>/usr/libexec/qemu-kvm</emulator>
    <disk type='file' device='disk'>
      <driver name='qemu' type='qcow2'/>
      <source file='/var/lib/libvirt/images/svirt-test-vm.qcow2'/>
      <target dev='vda' bus='virtio'/>
    </disk>
    <interface type='network'>
      <source network='default'/>
      <model type='virtio'/>
    </interface>
    <graphics type='vnc' port='-1' autoport='yes' listen='127.0.0.1'/>
    <console type='pty'>
      <target type='serial' port='0'/>
    </console>
  </devices>
</domain>

步骤2:导入配置并启动实例

所有操作通过virsh完成,全程无需调用virt-install:

  • 校验并注册虚拟机配置到libvirt,该步骤会自动为实例分配全局唯一的sVirt动态安全标签:
    virsh define /tmp/svirt-vm.xml
    
  • 确认sVirt标签已自动生成,执行以下命令能看到seclabel段类型为dynamic,标签值类似system_u:system_r:svirt_t:s0:c128,c456(末尾的c分类是每个实例专属,是sVirt实现跨实例隔离的核心):
    virsh dumpxml svirt-test-vm | grep -A 5 seclabel
    
  • 启动虚拟机实例:
    virsh start svirt-test-vm
    

步骤3:验证sVirt隔离生效

  • 检查QEMU进程安全上下文:执行ps auxZ | grep qemu-kvm | grep svirt-test-vm,确认进程运行在专属的svirt_t带独立分类的上下文下,而非通用qemu_t上下文。
  • 检查磁盘文件标签:执行ls -Z /var/lib/libvirt/images/svirt-test-vm.qcow2,确认磁盘文件被自动打上和进程匹配的svirt_image_t标签,其他虚拟机进程无权限读写该磁盘。
  • 权限校验测试:切换到其他运行中VM的sVirt上下文尝试读取该磁盘文件,会返回Permission denied,证明隔离规则生效。

注意事项

  • 禁止手动编辑libvirt自动生成的seclabel配置段,会导致sVirt隔离失效或虚拟机启动失败
  • 禁止绕过libvirt直接执行qemu-kvm命令启动实例,该方式不会触发sVirt标签配置,无任何sVirt安全防护
  • 挂载自定义ISO、透传主机设备时,需提前配置对应资源的SELinux上下文,否则会出现权限报错

内容的提问来源于stack exchange,提问作者Deekshith Reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 19:06:35