Skip to content

Step 1 of 8 · Proxmox and KVM

The qcow2 file is the virtual appliance as a disk image for KVM. It uses a virtio-scsi disk and a virtio network adapter.

  • Access to Downloads and requirements in sslbrain Cloud.
  • Room for a machine with 2 vCPU, 4 GB RAM and a 40 GB disk.
  • For a static address: the address with prefix, the gateway and the DNS servers.
  1. Log in to sslbrain Cloud and open Downloads and requirements.

  2. Click Download qcow2, and download the .sha256 file from the same page.

  3. Copy both files to the Proxmox or KVM host, and check the disk image:

    Terminal window
    sha256sum -c sslbrain-<version>.qcow2.sha256

Use SeaBIOS as the firmware.

Run the commands in a shell on the Proxmox host. Replace <vmid> with a free VM ID, <storage> with the storage the disk is to live on, and vmbr0 with your bridge.

  1. Create the machine without a disk:

    Terminal window
    qm create <vmid> --name sslbrain --cores 2 --memory 4096 \
    --net0 virtio,bridge=vmbr0 --scsihw virtio-scsi-pci \
    --bios seabios --ostype l26
  2. Import the disk image:

    Terminal window
    qm importdisk <vmid> sslbrain-<version>.qcow2 <storage>

    The import prints the disk’s name at the end, for example unused0:local-lvm:vm-<vmid>-disk-0.

  3. Attach the disk as scsi0 and boot from it. Use the name after unused0::

    Terminal window
    qm set <vmid> --scsi0 local-lvm:vm-<vmid>-disk-0 --boot order=scsi0
  4. If the disk is to be larger than 40 GB, grow it now:

    Terminal window
    qm resize <vmid> scsi0 +20G

Copy the disk image to libvirt’s image directory and create the machine. Replace br0 with your bridge.

Terminal window
virt-install --name sslbrain --vcpus 2 --memory 4096 \
--disk path=/var/lib/libvirt/images/sslbrain-<version>.qcow2,bus=scsi \
--controller type=scsi,model=virtio-scsi \
--network bridge=br0,model=virtio \
--os-variant ubuntu24.04 --import --noautoconsole

Without a seed disk, the appliance uses DHCP. A static address is passed on a small seed disk, which the appliance reads once, at first boot.

  1. Write a file called user-data. All keys are optional. Write one key per line, without quotation marks:

    #cloud-config
    hostname: sslbrain-01
    ip_address: 10.0.0.10/24
    gateway: 10.0.0.1
    dns: 10.0.0.53,10.0.0.54
  2. Create an empty meta-data next to it, and create the seed disk:

    Terminal window
    touch meta-data
    genisoimage -output seed.iso -volid cidata -joliet -rock user-data meta-data

    cloud-localds seed.iso user-data gives the same result.

  3. Attach the seed disk to the machine as a CD-ROM before you start it for the first time.

    On Proxmox: put seed.iso in an ISO storage, for example /var/lib/vz/template/iso/, and attach it:

    Terminal window
    qm set <vmid> --ide2 local:iso/seed.iso,media=cdrom

    With virt-install: add --disk path=seed.iso,device=cdrom to the command above.

The appliance uses only the four keys above. cloud-init is disabled, so users, SSH keys and network sections in the file are not used. After first boot the seed disk can be removed. From then on, you change the address with item 3 in the console menu (Console menu).

  1. Start the machine and open its display: Console in Proxmox, virt-manager, or virt-viewer sslbrain with libvirt.

  2. Wait a few minutes while the appliance expands the disk and downloads and checks its software.

  3. Open the address the console shows: Open https://<ip> in a browser to use it.

  4. The browser warns about the self-signed certificate. Continue to the page. The setup wizard opens with the Log in with sslbrain Cloud button.

To check the certificate’s fingerprint, see First boot. Then continue with 2. First-time setup.

  • The machine does not boot from the disk: check that the firmware is SeaBIOS and that scsi0 is first in the boot order.
  • The console shows “NO NETWORK ADDRESS”: DHCP has not given an address, and there is no seed disk. Set a static address with item 3 in the console menu.
  • The address from the seed disk is not applied: the appliance stays on DHCP and the console shows the reason.
  • The software cannot be downloaded: the machine must be able to reach the internet on port 443. Item 2 in the console menu tests the connection. See Network and firewall and No connection to sslbrain Cloud.