LINUXOR.SK ... open source notes ...

Xen on Debian 4 - from the first dom0 to a hardened host with service guests

category: learnz/xen · date: 2008-07-13 · updated: 2026-10-04 · author: LALA · theme: github

This Learning builds a Xen virtualisation host on Debian 4.0 (Etch) and the virtual machines on it. The 2007 articles do it in a virtual environment, to learn the parts; the 2008 articles do it again on a physical server, hardened, with a base image and two service guests.

noteThis is historical material from 2007 and 2008, kept as it was written. Debian 4.0, the Xen 3 packages and the xm tool are long out of support, so read it for how such a host is put together, not as a guide for a current distribution. Some links in the articles may no longer work.

Every article ends with a section Current practice, which says what has changed since and what to do instead today.

The levels

Each level ends with a small check. There is no time limit: when you can do what the check asks, go on to the next level.

LevelYou practiceYou have passed the level when
1 · UnderstandThe Xen vocabulary and its limitsYou can say what dom0, a domU and xm are
2 · HostInstalling dom0: partitions, the Xen packages, the network bridgeYou can describe what dom0 needs before the first guest can start
3 · GuestsA domU on LVM, routed and NAT-ed networking, backup with LVM snapshotsYou can explain how a running domU is backed up from a snapshot and restored
4 · ProductionA hardened dom0 on hardware, a base image, guests for WWW and DNSYou can explain why every guest is built from the base image, and what the firewall on dom0 lets through

Level 1 is article 1, level 2 is article 2, level 3 is articles 3 and 4, and level 4 is articles 5 to 8.

The articles

Read them in this order. Every article also exists in Slovak, the language it was written in; the (SK) link is at the top of each.

#ArticleWhat it is
1The basics of XEN virtualisationLevel 1: terms, limits and links
2Dom0Level 2: dom0 in a virtual environment
3DomULevel 3: creating a domU on LVM and connecting it to the network
4DomU - backup with LVM snapshotsLevel 3: backup, restore and cloning with LVM
5Dom0 - the physical hardwareLevel 4: dom0 on a physical server, with firewall, Bastille, Snort and monitoring
6DomU - Base (Golden image)Level 4: the base domU that other guests are made from
7DomU - WWW system - apache2 + mod_security2 + mod_suphp + php5 + php5_suhosinLevel 4: a web server guest
8DomU - DNS system - djbdnsLevel 4: a DNS guest with djbdns

What you will be able to do

Final check

Take one guest from article 7 or 8 and trace it back: which image it was built from, which logical volume holds it, how it reaches the network, and how you would restore it.