Offline VM intelligence and migration assurance. GuestKit reads a VM disk while the guest is off, scores first-boot readiness 0–100, repairs it through a plan you can read, and certifies cutover with a signed Passport.
6 disk formats · 0–100 boot score · 0 appliance daemons · 8 migration targets · Apache-2.0
Gallery · Docs · Product · Wiki · 30-day Enterprise trial
| Release | What changed |
|---|---|
| Agent (main) | Per-container eBPF network policy and BPF-LSM controls in the guest agent (guestkit.netpolicy / guestkit.lsm), off by default, audit first, enforce only under a time-bound lease |
| 1.2.5 | Offline inject on run_migrate_repair: hostname, network, users, services, first-boot scripts, cloud-init, AD rejoin, Windows KMS and RDP, appended to the repair plan |
| 1.2.5 | Online snapshots freeze the filesystem through the privileged helper, so KubeVirt snapshots of PVC-backed VMs work with the unprivileged agent |
| 1.2.5 | Linux agent connects to the virtio channel on stock distros (udev rule shipped in DEB, RPM and tarball); concurrent NBD mounts no longer race |
| 1.2.2 | Web Image Vault reaches TUI parity: inventory tabs, Assurance (plan, passport, repair preview and gated apply), Profiles and Files |
| 1.2.0 | guestkit-qemu assured QEMU/VirtIO runtime, guestkit vm, virtctl-guestkit guestfs, the cutover bundle and guestkit shrink for oversized disks |
Full history: CHANGELOG.md.
Every hypervisor exit fails the same way: you discover the disk was broken at 2am, in the cutover window, after power-on. GuestKit reads the disk while the guest is off — qcow2, VMDK, VHDX, VHD, VDI or raw — through its own pure-Rust engine (NBD or loop mount). There is no appliance daemon and no "power it on and see".
| When this happens… | GuestKit gives you… |
|---|---|
| "Will it boot?" is answered at power-on | An offline doctor score (0–100) with a root-cause chain for each blocker |
| Each migration relies on scripts and tribal knowledge | Structured plans in JSON/YAML and a CI gate on the same score |
| Cutover weekend is full of surprises | Hypervisor-aware migrate-plan and day-0 packs, for 8 targets |
| There is no audit trail of what was checked | A signed Cutover Passport per disk |
| Repairs are hand edits inside a mounted image | Fix plans you can read, applied with backups and rollback |
| Migration order is guessed by hand | fleet wave-plan: dependency-aware waves |
Fixes are never implicit. Repairs go through a plan you can read, applied with backups and rollback, and the same score drives the CI gate, the signed Cutover Passport, and assured QEMU launch.
|
Boot-readiness scoring First-boot probability 0–100, the blockers explained, and a reviewable fix plan. The cutover problem |
Offline repair Repairs go through a plan you can read, applied with backups and rollback. What you can do |
Migration assurance The same score drives the CI gate, the signed Cutover Passport and assured QEMU launch. Quick start |
|
Engine and formats A pure-Rust engine over qcow2, VMDK, VHDX, VHD, VDI and raw, through NBD or loop mount. Platform layout |
Suite hand-offs Export with Transiva, convert and deploy with h2kvm, assure with GuestKit, operate on Zorvia or Zeus OS. Who does what |
CLI, TUI, web, CI CLI, TUI, QEMU, Python, web console, in-guest agent and a GitHub Action. Run the web stack |
70+ commands · 6 disk formats · 0 appliance daemons · 8 migration targets · Apache-2.0
The full comparison has more rows, including fleet drift, the Carbon TUI with the in-guest agent, and guestkit qga as a drop-in for virsh qemu-agent-command.
| GuestKit | libguestfs + virt-v2v | |
|---|---|---|
| Disk access | Rust engine; guest files reached through qemu-nbd or loop mounts on the host |
Launches a small appliance VM to read and edit the disk |
| Boot readiness | doctor: a 0–100 first-boot score per target, with blockers explained |
Inspection and conversion; no readiness score |
| Migration plan | migrate-plan per target (kvm, proxmox, qemu, kubevirt, aws, azure, gcp, hyperv) |
virt-v2v converts a guest to run on KVM |
| Repair | Fix plans with backups and rollback; rescue for SSH, GRUB and passwords |
virt-customize, virt-rescue and guestfish for scripted edits |
| Cutover evidence | Signed Cutover Passport and a GitHub Action that fails below a score | Not part of the toolkit |
| Interfaces | CLI, TUI, Python, web console, in-guest agent, GitHub Action | CLI tools and language bindings |
| Choose libguestfs when | You need its broad filesystem and OS coverage, or virt-v2v's end-to-end conversion, and have no need for a score or a cutover record |
GuestKit sits next to conversion tools rather than replacing all of them: h2kvm converts and deploys, and calls GuestKit for the offline fixes.
Assurance: doctor score 78, a REVIEW decision, and ranked findings with a fix command each.
Summary: OS identity and inventory counts from inspect.
Image Vault: import a disk, or try the offline demo.
The bundled OSS web console rendering its offline demo data, not a live deployment. Demo videos are in the gallery.
disk.qcow2 / .vmdk / .vhdx / .vhd / .vdi / .raw
│
▼
┌──────────────────────┐
│ Pure-Rust engine │──► doctor 0–100 + blockers
│ NBD / loop mount │──► migrate-plan YAML
└──────────────────────┘──► Passport · repair · CI gate
│ guestkit-qemu (assured launch)
CLI · TUI · QEMU · Python · Web · Agent · GitHub Action
Export with Transiva (Apache-2.0) → convert & deploy with h2kvm (Zyvor Production License) → assure with GuestKit (Apache-2.0) → operate on Zorvia or Zeus OS. Run and manage VMs with FluxVM. Who does what · h2kvm integration
Architecture in depth: docs/architecture/overview.md.
# v1.2.5 GitHub Release — crates.io `guestkit` is still 0.3.2
curl -fsSL -O https://github.com/zyvorai/zyvor-guestkit/releases/download/v1.2.5/guestkit-1.2.5-linux-amd64.tar.gz
guestkit doctor vm.qcow2 --target proxmox --explain
guestkit migrate-plan vm.vmdk --target kvm --export plan.yaml
guestkit passport emit vm.qcow2 --target kvm -o passport.json
guestctl tui vm.qcow2 # Assurance · preview · export
guestkit-qemu plan vm.qcow2 --json # assurance → QEMU definitionCI gate — same score, no CLI install step:
- uses: zyvorai/guestkit@v1
with:
disk: vm.qcow2
target: kvm
fail-below: '80'Targets: kvm · proxmox · qemu · kubevirt · aws · azure · gcp · hyperv. Host needs: Linux with qemu-img, losetup, and qemu-nbd (mount/repair may need root).
Python (v1.1.0+), on PyPI: pip install zyvor-guestkit, then guestkit.run_doctor("vm.qcow2", target="kvm", explain=True). The full quick start, shrink and Python examples: docs/quick-start.md.
| Goal | Document |
|---|---|
| Docs site | zyvorai.github.io/zyvor-guestkit |
| Docs home | docs/README.md · INDEX |
| DevOps runbooks | docs/devops |
| Feature guide | guestkit-user-feature-guide.md |
| h2kvm integration | h2kvm integration |
| QEMU / VirtIO runtime | qemu-runtime.md |
| Dump virsh → GuestKit | virsh-to-guestkit.md |
| Architecture | overview |
The complete map, with the changelog and roadmap, is in docs/documentation-map.md.
- Gallery: console screenshots and demo videos — docs/gallery.md.
- Who does what: the suite split and the libvirt/virsh map — docs/who-does-what.md.
- h2kvm integration: docs/h2kvm-at-a-glance.md.
- What you can do: assure, plan, certify, repair, launch — docs/capabilities.md.
- Free web stack (GHCR): docs/web-stack-ghcr.md.
- Open source vs Enterprise: docs/oss-vs-enterprise.md.
- Platform layout: docs/platform-layout.md.
- Repository: docs/repository-layout.md.
- Prerequisites and build: docs/prerequisites-and-build.md;
docs/and this README are authoritative.
Open source — free under Apache-2.0. This repo · personal, lab, and commercial production. Full offline doctor, migrate-plan, repair, fleet, policy · CLI · TUI · Python · self-hosted web/workers.
Enterprise — buy for programs. Same engine — not a locked doctor. Command Center · Portfolio · Assurance · Migration Factory · Passport Authority · OIDC / RBAC / audit · SLA · air-gap · hypervisor exit workshops.
Open source vs Enterprise · Full feature matrix · 30-day Enterprise trial · Pricing
Trial expired or want a guided evaluation? Book a demo or start a 30-day PoC — no email needed. sales@zyvor.dev remains as a fallback.
GuestKit is at v1.2.5 (GitHub Release; PyPI zyvor-guestkit; crates.io guestkit is still 0.3.2). The architecture overview states the engine's scope plainly:
| Area | Status |
|---|---|
| Pure-Rust parsing: partition tables, filesystem signatures, evidence schema, boot engine, assurance APIs | Shipped |
Web UI (deploy/ui: inventory, Assurance, Profiles, Files), GHCR zyvor-ui |
Shipped |
| In-process QCOW2 read | Partial: format detection and selective reads; full cluster walk defers to qemu-nbd |
| File access inside guests | Through loop devices / qemu-nbd and a host mount, not in-process ext4/NTFS parsers |
guestkit shrink |
Narrow by design: a single/last ext2/3/4 partition, MBR or GPT, no LVM/LUKS; other layouts are reported and left untouched |
GHCR web stack (deploy/docker-compose.ghcr.yml) |
Eval only: unauthenticated, do not expose beyond localhost |
| Guest-agent eBPF policy and LSM | Opt-in: gated by capabilities.ebpf, off by default |
| Product | Role next to GuestKit |
|---|---|
| GuestKit | Offline VM assurance: boot score, repair, Cutover Passport |
| Transiva | Exports VMs out of the source hypervisor, upstream of GuestKit |
| h2kvm | Converts and deploys to KVM; uses the GuestKit Python package for offline fixes |
| Zorvia | KubeVirt VM platform to operate the migrated VMs |
| FluxVM | Runs and manages VMs; production run, network and TTL sit there, not in guestkit vm |
GuestKit is free and open source under the Apache License, Version 2.0. You may use, modify, and run it for personal, lab, and commercial production use at no charge, subject to Apache-2.0 (preserve notices / NOTICE where required). See NOTICE and docs/legal/ where applicable. That does not change.
Zyvor Enterprise adds what production teams ask for: supported releases, deployment and upgrade guidance, priority incident triage, a named technical contact and 24x7 critical intake. Production support, SLAs, and Zyvor Enterprise products are licensed separately. Plans and terms: docs/SUBSCRIPTION-MODEL.md · Pricing · sales@zyvor.dev.
Report vulnerabilities privately per SECURITY.md. More at zyvor.dev/guestkit · docs · blog.


