VRT-101 · Virtualization & Containers
KVM Internals
How Linux becomes a hypervisor: vCPU execution, memory virtualisation and the QEMU relationship.
Who this course is for
Platform, cloud and virtualisation engineers who operate KVM hosts and need to reason about guest behaviour from the hypervisor's side — exits, memory and interrupts — rather than treating the VM as a black box.
Prerequisites
Course outline
Day 1 — Hardware virtualisation and the vCPU run loop
- VMX/SVM operation model: root vs non-root mode, VMCS/VMCB
- Entering and leaving guest mode: VMLAUNCH/VMRESUME and what the hardware saves
- The /dev/kvm API: VMs, vCPUs and memory slots as file descriptors
- The KVM vCPU run loop read in source
- kvm.ko organisation and the arch-specific boundary
Day 2 — VM exits and their cost
- Exit reasons and where each comes from: I/O instructions, MSR access, page faults, interrupts
- Counting and classifying exits with kvm_stat and kvm tracepoints
- What an exit costs and how to measure it
- Reducing exits: paravirt interfaces, MSR bitmaps, avoiding unnecessary traps
- The exit-cost argument behind virtio
Day 3 — Memory virtualisation
- EPT/NPT second-level translation and the nested walk cost
- Shadow paging: how it works and when it still matters
- TLB management, invalidation and VPID/ASID tagging
- Huge pages for guests and why they matter more under virtualisation
- Overcommit, ballooning and KSM: what each trades away
Day 4 — Interrupts, QEMU and migration
- Virtual APIC and the cost of interrupt injection
- APICv, posted interrupts and what they offload
- irqfd/eventfd fast paths between host and guest
- QEMU's role: machine types, device models and the monitor
- Live migration basics: dirty page tracking and convergence
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: boot a minimal guest on /dev/kvm with a small C VMM — no QEMU — and handle its VM exits yourself
- Lab: count and classify VM exits with kvm_stat and ftrace kvm tracepoints, then apply an exit-reduction technique and re-measure
- Lab: measure nested page fault cost and the effect of huge-page-backed guest memory on a memory-bound workload
- Lab: trace an interrupt's path into a guest with and without posted interrupts enabled
- Lab: live-migrate a busy VM between two QEMU instances and watch dirty-page tracking converge
Capstone project
Build and instrument a minimal VMM against /dev/kvm that boots a small guest binary: set up vCPUs and guest memory, handle the exits your guest produces, and measure exit frequency and cost for a workload you choose. The deliverable is the VMM source, the exit statistics, and a short report explaining each exit class you saw and how you would eliminate it — the same reasoning you then apply to a production QEMU/KVM guest.
What you leave with
- A working mental model of the vCPU run loop, grounded in source you have read
- The ability to count, classify and cost VM exits on a real host
- Hands-on /dev/kvm API experience from writing your own VMM
- An evidence-based view of EPT, APICv and huge pages — measured, not assumed
- Fluency with kvm_stat and kvm tracepoints for production diagnosis
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Platform, cloud and virtualisation engineers who operate KVM hosts and need to reason about guest behaviour from the hypervisor's side — exits, memory and interrupts — rather than treating the VM as a black box. It sits at advanced level within the Virtualization & Containers track.
What do I need to know already?
Specific prerequisites for this course: Solid C and Linux systems programming; Comfort reading kernel source; x86 or Arm assembly basics helpful. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 4 full days with hardware on your desk, capped at 14. Online is 8 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 18 Oct – 21 Oct 20264 full days | RiyadhIn person · KAFD Conference Centre | 8 of 14 | — | SAR 12,000 | |
| 18 Oct – 21 Oct 20264 full days | Kuwait CityIn person · Al Hamra Tower | 3 of 14 | — | KWD 990 | |
| 25 Oct – 28 Oct 20264 full days | MuscatIn person · Knowledge Oasis Muscat | 8 of 14 | — | OMR 1,230 | |
| 1 Nov – 10 Nov 20268 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 16 of 20 | — | US$2,300 | |
| 2 Nov – 5 Nov 20264 full days | OttawaIn person · Kanata North Tech Park | 3 of 14 | — | CAD 4,350 | |
| 2 Nov – 5 Nov 20264 full days | TorontoIn person · MaRS Discovery District | 8 of 14 | — | CAD 4,350 | |
| 2 Nov – 11 Nov 20268 half-days | Europe bandLive online · 09:00–13:00 CET | 5 of 20 | — | US$2,300 | |
| 9 Nov – 12 Nov 20264 full days | LondonIn person · Shoreditch Works | 3 of 14 | GBP 2,250until 10 Oct | ||
| 9 Nov – 18 Nov 20268 half-days | Americas bandLive online · 13:00–17:00 ET | 10 of 20 | US$2,070until 10 Oct | ||
| 16 Nov – 19 Nov 20264 full days | BerlinIn person · Factory Görlitzer Park | 8 of 14 | EUR 2,650until 17 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Virtualization & Containers
VRT-1103 days
VFIO & Device Passthrough
Giving a guest direct access to real hardware — the mechanism behind GPU passthrough.
Practitioner-taught
SAR 9,000Next 15 Nov
VRT-1203 days
virtio Device Drivers
The paravirtualised device model: virtqueues, transports and writing a virtio driver.
Practitioner-taught
SAR 9,000Next 1 Nov
VRT-2013 days
Namespaces & cgroups from Scratch
Build a container by hand with the primitives, so the abstraction stops being magic.
Practitioner-taught
SAR 7,880Next 8 Nov
VRT-2103 days
Container Runtimes & the OCI Spec
What runc, containerd and the OCI specifications actually define, and how images become running processes.
Practitioner-taught
SAR 7,880Next 18 Oct
VRT-2203 days
Container Security & seccomp
Making containers a real security boundary rather than an organisational one.
Practitioner-taught
SAR 9,000Next 22 Nov