Qubes server?

156 views
Skip to first unread message

Manuel Amador (Rudd-O)

unread,
Jul 30, 2016, 8:05:02 PM7/30/16
to qubes-users
Hello!

I want to roll my own Qubes server — software-defined networking, remote
VM management, all the goodies that come with Qubes like volatile VMs
and VM templates — but I have had real trouble writing code to "undo"
some of the features of Qubes that make routing and firewalling
essentially client-only.

Is there someone working on this, on upstreaming the improvements, and
on remote management?

I can see there's a market for it, and I certainly need it. I would
hate to roll-my-own based on, say, Fedora or Debian, and having to redo
all the work that Qubes has done w.r.t. securing machines.

Thanks.

--
Rudd-O
http://rudd-o.com/

Iestyn Best

unread,
Jul 31, 2016, 8:48:27 PM7/31/16
to qubes-users, rud...@rudd-o.com
Hi,

I have been interested in an idea like that as I could see it beneficial for many organisations but currently I have had no actual driving need for it at this time.

I would be interested in hearing of something like this is happening or even possible.

Appreciate all the work the Qubes team has been doing.

Regards,
Iestyn Best

Andrew

unread,
Aug 8, 2016, 4:57:32 PM8/8/16
to qubes...@googlegroups.com
Iestyn Best:
Not exactly the subject at hand, but this might be relevant to your
interests: https://github.com/kbrn/qubes-app-dom0-shell

You can use this to SSH into some Qubes AppVM, use the RPC service to
get a Dom0 shell, and from there jump into some other VM shell, or do
whatever you need.

Andrew

Manuel Amador (Rudd-O)

unread,
Aug 10, 2016, 9:06:00 AM8/10/16
to qubes...@googlegroups.com
I wrote something like that years ago:

https://github.com/Rudd-O/ansible-qubes

It was meant to power Ansible configuration of VMs, but the base program
is basically an inter-VM SSH clone.

--
Rudd-O
http://rudd-o.com/

Manuel Amador (Rudd-O)

unread,
Oct 12, 2016, 1:34:29 PM10/12/16
to qubes...@googlegroups.com
On 07/31/2016 12:04 AM, Manuel Amador (Rudd-O) wrote:
> Hello!
>
> I want to roll my own Qubes server — software-defined networking, remote
> VM management, all the goodies that come with Qubes like volatile VMs
> and VM templates — but I have had real trouble writing code to "undo"
> some of the features of Qubes that make routing and firewalling
> essentially client-only.
>
> Is there someone working on this, on upstreaming the improvements, and
> on remote management?

For people coming through search engines:

https://github.com/Rudd-O/qubes-network-server


--
Rudd-O
http://rudd-o.com/

Reply all
Reply to author
Forward
0 new messages