VRT-101 · Virtualization & Containers

KVM Internals

How Linux becomes a hypervisor: vCPU execution, memory virtualisation and the QEMU relationship.

Advanced 4 days in person8 half-days online Max 14 in person

Who this course is for

Platform, cloud and virtualisation engineers who operate KVM hosts and need to reason about guest behaviour from the hypervisor's side — exits, memory and interrupts — rather than treating the VM as a black box.

Prerequisites

Solid C and Linux systems programmingComfort reading kernel sourcex86 or Arm assembly basics helpful

Course outline

Day 1 — Hardware virtualisation and the vCPU run loop

  • VMX/SVM operation model: root vs non-root mode, VMCS/VMCB
  • Entering and leaving guest mode: VMLAUNCH/VMRESUME and what the hardware saves
  • The /dev/kvm API: VMs, vCPUs and memory slots as file descriptors
  • The KVM vCPU run loop read in source
  • kvm.ko organisation and the arch-specific boundary

Day 2 — VM exits and their cost

  • Exit reasons and where each comes from: I/O instructions, MSR access, page faults, interrupts
  • Counting and classifying exits with kvm_stat and kvm tracepoints
  • What an exit costs and how to measure it
  • Reducing exits: paravirt interfaces, MSR bitmaps, avoiding unnecessary traps
  • The exit-cost argument behind virtio

Day 3 — Memory virtualisation

  • EPT/NPT second-level translation and the nested walk cost
  • Shadow paging: how it works and when it still matters
  • TLB management, invalidation and VPID/ASID tagging
  • Huge pages for guests and why they matter more under virtualisation
  • Overcommit, ballooning and KSM: what each trades away

Day 4 — Interrupts, QEMU and migration

  • Virtual APIC and the cost of interrupt injection
  • APICv, posted interrupts and what they offload
  • irqfd/eventfd fast paths between host and guest
  • QEMU's role: machine types, device models and the monitor
  • Live migration basics: dirty page tracking and convergence

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: boot a minimal guest on /dev/kvm with a small C VMM — no QEMU — and handle its VM exits yourself
  2. Lab: count and classify VM exits with kvm_stat and ftrace kvm tracepoints, then apply an exit-reduction technique and re-measure
  3. Lab: measure nested page fault cost and the effect of huge-page-backed guest memory on a memory-bound workload
  4. Lab: trace an interrupt's path into a guest with and without posted interrupts enabled
  5. Lab: live-migrate a busy VM between two QEMU instances and watch dirty-page tracking converge

Capstone project

Build and instrument a minimal VMM against /dev/kvm that boots a small guest binary: set up vCPUs and guest memory, handle the exits your guest produces, and measure exit frequency and cost for a workload you choose. The deliverable is the VMM source, the exit statistics, and a short report explaining each exit class you saw and how you would eliminate it — the same reasoning you then apply to a production QEMU/KVM guest.

What you leave with

  • A working mental model of the vCPU run loop, grounded in source you have read
  • The ability to count, classify and cost VM exits on a real host
  • Hands-on /dev/kvm API experience from writing your own VMM
  • An evidence-based view of EPT, APICv and huge pages — measured, not assumed
  • Fluency with kvm_stat and kvm tracepoints for production diagnosis

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Platform, cloud and virtualisation engineers who operate KVM hosts and need to reason about guest behaviour from the hypervisor's side — exits, memory and interrupts — rather than treating the VM as a black box. It sits at advanced level within the Virtualization & Containers track.

What do I need to know already?

Specific prerequisites for this course: Solid C and Linux systems programming; Comfort reading kernel source; x86 or Arm assembly basics helpful. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 4 full days with hardware on your desk, capped at 14. Online is 8 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 21 Oct 20264 full days RiyadhIn person · KAFD Conference Centre 8 of 14 —SAR 12,000
18 Oct – 21 Oct 20264 full days Kuwait CityIn person · Al Hamra Tower 3 of 14 —KWD 990
25 Oct – 28 Oct 20264 full days MuscatIn person · Knowledge Oasis Muscat 8 of 14 —OMR 1,230
1 Nov – 10 Nov 20268 half-days Gulf bandLive online · 09:00–13:00 GMT+3 16 of 20 —US$2,300
2 Nov – 5 Nov 20264 full days OttawaIn person · Kanata North Tech Park 3 of 14 —CAD 4,350
2 Nov – 5 Nov 20264 full days TorontoIn person · MaRS Discovery District 8 of 14 —CAD 4,350
2 Nov – 11 Nov 20268 half-days Europe bandLive online · 09:00–13:00 CET 5 of 20 —US$2,300
9 Nov – 12 Nov 20264 full days LondonIn person · Shoreditch Works 3 of 14 GBP 2,250until 10 OctGBP 2,500
9 Nov – 18 Nov 20268 half-days Americas bandLive online · 13:00–17:00 ET 10 of 20 US$2,070until 10 OctUS$2,300
16 Nov – 19 Nov 20264 full days BerlinIn person · Factory Görlitzer Park 8 of 14 EUR 2,650until 17 OctEUR 2,940

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Virtualization & Containers