Certification
This provider is certified: it passes every behavior in the BigFleet conformance program — the same bar every provider must clear — so you can trust it to create, configure, drain, and delete machines correctly under load, failure, and restart. You do not need to run anything here to use it in production; this page exists if you want to reproduce that verdict yourself.
“Certified” here means exactly what it means in the conformance program: the provider passes both the upstream authoritative baseline and this repo’s extension suite, with no failures and no skipped-as-failed behaviors.
One command
make certify-libvirtThat target (hack/run-certify.sh libvirt) is fully credential-free. It:
- Resolves the bigfleet checkout that owns the authoritative contract — reusing
$BIGFLEET_SRCif set, otherwise cloning the exact version pinned in the provider’sgo.modinto.cache/bigfleet-src. - Builds
./bin/libvirtand boots it with--provider=certify --seed-count=256. It uses--use-fake-backend, so no hypervisor is touched — the extension suite consumes a fresh machine per behavior, hence the generous seed. - Runs the upstream baseline (
test/conformance/in the bigfleet repo), then the extension suite (conformance/suite, build-taggedcertify), both dialing that one endpoint. - Prints
CERTIFIED: libvirt passed the upstream baseline + the extension suite— or fails non-zero on the first failing behavior, tearing the provider down.
Override the port with PORT=....
Profiles the libvirt provider claims
The harness certifies a provider against the profiles it advertises; behaviors outside a claimed profile skip-as-pass.
- core — every provider (lifecycle, errors, fencing, concurrency, metadata, field-shape, list, property).
- cloud — implements
Delete(Idle → Speculative). The defaulton_demandlibvirt pool does (Delete=virDomainDestroy+virDomainUndefine+ overlay delete is meaningful), so it claims cloud. If you run a fixed--capacity-type bare_metalpool instead, you claim bare-metal andDeleteis never sent (M73). - spot — exposes SPOT capacity. Local KVM has no preemption market, so the
provider does not claim
spot; the SPOT-interruption_probability > 0behaviors skip-as-pass. See Pricing & interruption for why a zero interruption probability is the correct value here. - fault / durable / scale — failure→
FAILED, restart recovery, and scale lanes. These come fromproviderkitand pass by construction for any kit-based provider; run them through the report runner.
make certify-libvirt runs the credential-free core gate (baseline + the
black-box extension). The complete certification — every applicable lane —
runs through the bfconformance runner and emits a JUnit + JSON report with a
verdict:
make report-libvirt PROFILE=core,cloud# -> VERDICT: CERTIFIED, writes conformance-report/libvirt/{report.json,junit.xml}Running the full multi-lane set confirms the kit-provided lanes pass too:
make report-libvirt PROFILE=core,cloud,fault,durable,scale# behaviors: 93 total — 93 passed, 0 failed, 0 skipped, 0 not-implemented# -> VERDICT: CERTIFIEDCertifying a real endpoint
make certify-libvirt certifies the fake backend in CI. To certify the provider
talking to real libvirt, run it yourself against your hosts and point the
extension suite at it:
# 1. Boot the provider against real libvirt (see Install & deploy / Configuration)../bin/libvirt \ --addr 127.0.0.1:9099 \ --connect 'rack1=qemu+libssh://bigfleet@host-a/system?keyfile=./id_ed25519&known_hosts=./known_hosts&known_hosts_verify=normal' \ --image ubuntu-24.04.qcow2 \ --offerings ./offerings.json
# 2. In another shell, run the extension suite against that endpoint.go -C conformance test -tags=certify -count=1 ./suite/... -target=127.0.0.1:9099A real run exercises the full lifecycle — define + start → wait-running →
guest-agent Configure/Drain → destroy + undefine — so the endpoint needs a
reachable host (see Credentials) and a base
image that runs qemu-guest-agent and ships the bootstrap hook. It will create
and destroy real domains; certify against a throwaway host and clean up
afterwards.
See also
- Conformance program — the behavior registry, profiles, and how to add a behavior.
- Pricing & interruption — why
interruption_probabilityis a genuine zero on local KVM. - Credentials & auth — the libvirt connection a real-endpoint certification run needs.