{
    "product": "Cenvero Stratum",
    "generated_at": "2026-10-10T15:57:43+00:00",
    "format": "cenvero-docs-v1",
    "document_count": 1,
    "documents": [
        {
            "slug": "compute/limits",
            "title": "Current Limits",
            "category": "Compute",
            "url": "https://www.stratum.cenvero.com/docs/compute/limits",
            "headings": [
                {
                    "level": 1,
                    "text": "Current Limits"
                },
                {
                    "level": 2,
                    "text": "Servers"
                },
                {
                    "level": 2,
                    "text": "Guests"
                },
                {
                    "level": 2,
                    "text": "Storage"
                },
                {
                    "level": 2,
                    "text": "Networking"
                },
                {
                    "level": 2,
                    "text": "Management"
                },
                {
                    "level": 2,
                    "text": "Security notes"
                },
                {
                    "level": 2,
                    "text": "See also"
                }
            ],
            "word_count": 932,
            "markdown": "# Current Limits\n\nCompute is in early access. This page lists what it does not do yet, so you can\nplan around it. It changes as the work lands; [Releases](/releases) says what\neach build adds.\n\n> Part of [Compute](/docs/compute/overview), in early access.\n\n## Servers\n\n- **x86_64 only.** Nodes on other processors (arm64) run networking normally and\n  report Compute as unavailable.\n- **Hardware virtualization.** KVM with Intel VT-x or AMD-V is what Compute is\n  built for. Without it machines run in software emulation, many times slower —\n  for trying things out only (`CENVERO_ALLOW_EMULATION=1` at install).\n- **Tested on Debian 13 so far.** Debian 12 and Ubuntu 22.04/24.04 install the\n  same way; RHEL-family hosts are not validated for Compute yet.\n- **A machine stays on its node.** Each node runs its own machines. In a\n  [cluster](/docs/clustering/overview) you see and manage every member's\n  machines from any member, but you choose the node a machine is created on:\n  there is no automatic placement, and machines cannot move between nodes. A\n  tenant's `max_vms` cap counts per node.\n\n## Guests\n\n- **Linux cloud images are what is tested.** UEFI, secure boot and a TPM 2.0\n  can be chosen at create ([Firmware](/docs/compute/machine-settings)), but\n  Windows guests have not been validated yet. The firmware and the TPM cannot be\n  changed after the machine is created.\n- **Resizing.** CPUs and memory can be changed on an existing machine; a running\n  one grows live only up to the maximums it was created with, anything else\n  applies at its next restart ([Changing a machine's\n  size](/docs/compute/machine-settings)). Fewer vCPUs, and more vCPUs on a\n  machine with secure boot, always wait for a restart. The disk can only grow,\n  while the machine is stopped.\n- **Extra disks are volumes.** A machine boots from one disk; more space is\n  added as volumes, which can be attached, grown, snapshotted and backed up\n  ([The Web Console](/docs/compute/web-console)). Volumes, snapshots and\n  backups come with Compute ([Licensing](/docs/licensing)). On a machine\n  created before its node's licence included volumes, attach the first volume\n  while the machine is stopped; after that, volumes attach while it runs.\n- **Interfaces can be added and removed while a machine runs.** A machine\n  created before this was possible needs one restart before an interface can\n  be added to it while it runs, and a new interface has to be configured inside\n  the guest.\n- **Guest agent:** setting an account's password and reading the guest's own\n  addresses work; nothing else uses the guest agent yet.\n\n## Storage\n\n- **Snapshots and backups are for volumes, not the boot disk.** Keep data that\n  matters on a volume. The node's own backups cover its configuration and\n  records, not disks. Deleting a machine deletes its boot disk for good.\n- **Backups stay on the same server,** in its disk pool, so they do not protect\n  against losing the server. Copying backups to another server is not\n  available yet.\n- **Disks are thin.** They grow as the guest writes; a full pool pauses the\n  guests that write (see [Lifecycle](/docs/compute/lifecycle)). A tenant's\n  volumes can be capped per node (`tenant quota-set <id> --max-volumes N\n  --max-volume-gib N`); boot disks have no per-tenant quota yet — watch\n  `compute status`.\n- **Images:** qcow2 or raw, self-contained, up to 50 GiB, fetched over HTTP(S)\n  with a SHA-256 or copied from a file on the node.\n\n## Networking\n\n- **Public addresses are IPv4 only**, and only the \"routed to the server's main\n  address\" kind most providers sell; addresses that need their own MAC address\n  on the uplink are not supported. DHCP does not hand out public addresses.\n- **Per-machine bandwidth limits** are refused for a tenant that has a bandwidth\n  cap (the tenant's cap applies instead).\n- **Only machines under a tenant are separated at their port**; operator\n  machines (no tenant) are not. Across nodes, separation is the overlay\n  network's job.\n- **Only a tenant's machines are held to their own addresses.** A tenant\n  machine may send IPv4 only from its network address or its public address\n  ([Tenants](/docs/tenants)); an operator machine (no tenant) may send from any\n  address no workload has claimed. IPv6 sources are not checked yet.\n- **Docker on the same server** is handled: the node lets its own workload\n  traffic through the firewall Docker switches on, and nothing else\n  ([Operations](/docs/operations)).\n\n## Management\n\n- **One console per node, or one for a whole cluster.** Each node serves its own\n  [web console](/docs/compute/web-console). Join the nodes into a\n  [cluster](/docs/clustering/overview) and any member's console manages every\n  member, machine consoles included.\n- **Customers cannot create their own machines yet.** With a tenant key they\n  can start, stop and restart their machines, open their consoles and reset a\n  password in the [customer portal](/docs/compute/web-console#a-portal-for-your-customers);\n  creating, resizing and deleting machines goes through you. A tenant key works\n  on the node that issued it, also in a cluster.\n- **The Cenvero panel does not manage your machines.** Like the rest of Stratum,\n  machines are managed on your nodes; the panel only issues licences.\n- **A tenant's suspension stops its machines** (and cuts their traffic); the\n  resume starts the ones that were running. Their disks stay as they are — a\n  suspension deletes nothing.\n\n## Security notes\n\n- **Image checks run as root on the node.** Registered images are checked\n  (SHA-256, format, no backing or external data file) before any machine uses\n  them; register images only from sources you trust.\n- **Deleting does not wipe.** A deleted machine's disk space is released without\n  being overwritten.\n\n## See also\n\n- [Compute overview](/docs/compute/overview)\n- [Tenants & Bandwidth](/docs/tenants)\n"
        }
    ]
}