{
    "product": "Cenvero Stratum",
    "generated_at": "2026-10-10T15:54:31+00:00",
    "format": "cenvero-docs-v1",
    "document_count": 1,
    "documents": [
        {
            "slug": "compute/machine-settings",
            "title": "Firmware, Resizing, Interfaces and the Guest Agent",
            "category": "Compute",
            "url": "https://www.stratum.cenvero.com/docs/compute/machine-settings",
            "headings": [
                {
                    "level": 1,
                    "text": "Firmware, Resizing, Interfaces and the Guest Agent"
                },
                {
                    "level": 2,
                    "text": "Firmware: BIOS or UEFI, secure boot and a TPM"
                },
                {
                    "level": 2,
                    "text": "Changing a machine's size"
                },
                {
                    "level": 2,
                    "text": "Adding and removing network interfaces"
                },
                {
                    "level": 2,
                    "text": "If an interface is removed behind Stratum's back"
                },
                {
                    "level": 2,
                    "text": "The guest agent"
                },
                {
                    "level": 3,
                    "text": "Setting a password"
                },
                {
                    "level": 2,
                    "text": "The same over the API"
                },
                {
                    "level": 2,
                    "text": "See also"
                }
            ],
            "word_count": 1538,
            "markdown": "# Firmware, Resizing, Interfaces and the Guest Agent\n\nThis page covers what you can change on a virtual machine after you create it —\nits vCPUs and memory, its network interfaces — the firmware options you choose\nwhen you create it (UEFI, secure boot, a TPM), and what the guest agent inside a\nmachine lets you do: set a password, see the guest's own addresses.\n\n> Part of [Compute](/docs/compute/overview), in early access. The commands\n> below run on the node, as root; every change needs a licence that includes\n> Compute and is not frozen. Looking at a machine never does. Creating a machine\n> is on [Creating virtual machines](/docs/compute/virtual-machines).\n\n## Firmware: BIOS or UEFI, secure boot and a TPM\n\nA machine starts with BIOS firmware unless you ask for UEFI. Windows 11 needs\nUEFI with secure boot and a TPM 2.0:\n\n```bash\nsudo cenvero-str-ctl vm create --name win11 --image img-5d2c90a1 --vcpus 4 --memory 8192 --disk 64 \\\n  --network net-8b1f03 --firmware uefi --secure-boot --tpm\n```\n\n| Option | What the machine gets |\n|---|---|\n| `--firmware bios` | BIOS firmware. The default, and what every machine had before this option existed. |\n| `--firmware uefi` | UEFI firmware, with its own settings store (boot order, secure boot keys) kept on the node. |\n| `--secure-boot` | UEFI with secure boot on and the usual Microsoft keys enrolled, so signed boot loaders (Windows, and Linux distributions with a signed shim) boot. Needs `--firmware uefi`. |\n| `--tpm` | A TPM 2.0 device, emulated per machine, its contents kept on the node. Works with either firmware. |\n\nThe firmware and the TPM are chosen at create and cannot be changed later: a\nguest installed under one firmware does not boot under the other, and a guest\nmay seal keys (a disk encryption key, for example) to its TPM. Deleting the\nmachine deletes its firmware settings and its TPM contents with it.\n\nIf the node cannot provide an option you ask for, the create is refused with a\nplain message, for example *this host cannot give a virtual machine a TPM: the\nTPM emulator is not installed*. The installer's `compute` and `suite` profiles\ninstall UEFI and TPM support; re-run the installer with one of them to add it.\nOn a server that already runs another panel's virtual machines, the installer\nlists what is missing instead of installing it (see [Compute](/docs/compute/overview#installing-with-compute)).\n`compute status` lists what the node supports:\n\n```json\n\"hypervisor\": { \"virt\": \"kvm\", \"firmware\": [\"bios\", \"uefi\"], \"secure_boot\": true, \"tpm\": true }\n```\n\n## Changing a machine's size\n\n```bash\nsudo cenvero-str-ctl vm update vm-3f9a1c2e --vcpus 4 --memory 8192\n```\n\nA stopped machine takes the new size when it next starts. A running machine\nchanges at once where it can, within the **maximums** it runs with:\n\n| Change on a running machine | When it applies |\n|---|---|\n| More vCPUs, up to the maximum | At once: the vCPUs are plugged in. Bringing them online is the guest's job; most Linux cloud images do it on their own. |\n| More or less memory, up to the maximum | At once, through the memory balloon (the guest needs its balloon driver, which Linux has built in). |\n| Fewer vCPUs | At the next restart. |\n| More vCPUs on a machine with secure boot | At the next restart. |\n| Anything above a maximum | At the next restart, which raises the maximum with it. |\n\nThe maximums are what a machine can grow to without a restart. They are the\nsize you create it with, unless you give room to grow at create:\n\n```bash\nsudo cenvero-str-ctl vm create --name web-01 --image img-5d2c90a1 --vcpus 2 --memory 2048 \\\n  --max-vcpus 8 --max-memory 16384 --network net-8b1f03\n```\n\n`vm update` answers with what changed at once and what waits:\n\n```json\n{\n  \"status\": \"updated\",\n  \"applied\": [\"vcpus 2→4\", \"memory 2048→4096 MiB\"],\n  \"pending_restart\": [],\n  \"vm\": { \"id\": \"vm-3f9a1c2e\", \"vcpus\": 4, \"max_vcpus\": 8, \"memory_mib\": 4096, \"max_memory_mib\": 16384, \"flags\": [] }\n}\n```\n\nA machine with changes waiting carries the flag `pending_restart` until it is\nrestarted with `vm restart` (a restart from inside the guest keeps the machine\nrunning and does not apply them). The new size is recorded at once, so it\nsurvives an agent restart and a host reboot.\n\n## Adding and removing network interfaces\n\nA machine can have up to four interfaces. Add one to a running or stopped\nmachine, on a managed network (at the next free address, or `NET=IP` for a\ngiven one) or with a [routed public address](/docs/networking/public-addresses):\n\n```bash\nsudo cenvero-str-ctl vm nic add vm-3f9a1c2e --network net-8b1f03=10.20.0.25\nsudo cenvero-str-ctl vm nic add vm-3f9a1c2e --public-ip auto --bandwidth-mbps 200\n```\n\nEverything that protects an interface is in place before the machine sees it:\nthe address is bound to the interface, the port is locked to it, and a tenant's\ninterface is isolated from every other tenant — exactly as for the interfaces\nthe machine was created with. A running machine sees the new interface at once;\na stopped one at its next start.\n\n**Configure the new interface in the guest.** The network configuration a\nmachine receives at its first boot covers only the interfaces it had then. A\nLinux guest shows the new interface (look it up by its MAC address, which\n`vm show` lists), but gives it no address by itself. Either configure it in the\nguest — for example with netplan, matching the MAC address:\n\n```yaml\nnetwork:\n  version: 2\n  ethernets:\n    extra0:\n      match: { macaddress: \"02:ce:0a:14:00:19\" }\n      addresses: [10.20.0.25/24]\n```\n\n— or let the guest ask for an address by DHCP, on a network that offers it\n(`network create … --host-gateway --dhcp`). Match interfaces by MAC address\nrather than by name: the name a guest gives an interface added while it runs\ncan differ from the one it gives it after a restart.\n\nRemove an interface by its index, its interface name or its address:\n\n```bash\nsudo cenvero-str-ctl vm nic remove vm-3f9a1c2e 1\n```\n\nA running machine is asked to release the interface first, and nothing is\nremoved until it has: if the guest does not let go (it may still be booting),\nthe command says so and changes nothing — try again, or remove the interface\nwhile the machine is stopped. A machine keeps at least one interface.\n\n**Machines created before this version** have no free slot for an interface\nadded while they run. `vm nic add` then says so and asks for one restart\n(`vm restart`); after it, adding works while the machine runs. Adding to a\nstopped machine always works.\n\n## If an interface is removed behind Stratum's back\n\nEvery machine's interface on the node is watched. If one is deleted outside\nStratum, it is recreated and secured again (address binding, port lock, tenant\nisolation) within about half a minute, and a running machine is reconnected to it\nwithout a restart: the guest keeps its interface, its address and its connections. To do\nit at once rather than wait:\n\n```bash\nsudo cenvero-str-ctl vm nic replug vm-3f9a1c2e 0\n```\n\nIf several interfaces of one machine are removed at once and they cannot be\ntold apart, the machine is flagged `network_degraded` instead; restart it to\nreconnect them.\n\n## The guest agent\n\nThe guest agent is a small service inside the machine that the node talks to\ndirectly, without the network. Many cloud images include it; otherwise install\nyour distribution's guest agent package in the guest (Windows guests get it with\nthe guest tools). Nothing depends on it for the machine to run; without it, the\ncommands below say that it does not answer.\n\nSee whether it answers, and the addresses the guest itself reports:\n\n```bash\ncenvero-str-ctl vm guest-agent vm-3f9a1c2e\n```\n\n```json\n{\n  \"vm\": \"vm-3f9a1c2e\",\n  \"guest_agent\": {\n    \"state\": \"responding\",\n    \"interfaces\": [\n      { \"name\": \"lo\", \"mac\": \"00:00:00:00:00:00\", \"addresses\": [\"127.0.0.1/8\", \"::1/128\"] },\n      { \"name\": \"enp1s0\", \"mac\": \"02:ce:0a:14:00:32\", \"addresses\": [\"10.20.0.50/24\"] }\n    ]\n  }\n}\n```\n\n`vm show` includes the same `guest_agent` section. Its `state` is `responding`,\n`not_connected` (no agent runs in the guest), `not_responding`, or\n`vm_not_running`.\n\n### Setting a password\n\nSet the password of an account in a running machine — for example to log in on\nits console after losing an SSH key:\n\n```bash\nsudo cenvero-str-ctl vm password vm-3f9a1c2e --user debian\nNew password:\nRetype it:\n```\n\nThe password is asked for twice, or read from the first line of standard input\nwhen that is not a terminal (`printf '%s\\n' \"$PW\" | sudo cenvero-str-ctl vm password …`).\nIt is never taken from the command line, so it never appears in a process list,\nand Stratum neither logs nor stores it; the change itself is recorded as a\nsecurity event (who, which machine, which account). The account must exist in\nthe guest.\n\n## The same over the API\n\nEvery command above has an API call (`/api/v1`, with an operator token). A\npassword travels only in the request body.\n\n| Method | Path | Body |\n|---|---|---|\n| POST | `/vms/{id}/update` | `{\"vcpus\": 4, \"memory_mib\": 8192}` (either may be left out) |\n| POST | `/vms/{id}/nics` | `{\"network_id\": \"net-8b1f03\", \"ip\": \"10.20.0.25\"}` or `{\"public_ip\": \"auto\"}`, optionally `\"bandwidth_mbps\"` |\n| DELETE | `/vms/{id}/nics/{nic}` | — (`{nic}`: index, interface name or address) |\n| POST | `/vms/{id}/nics/{nic}/replug` | — |\n| POST | `/vms/{id}/password` | `{\"user\": \"debian\", \"password\": \"…\"}` |\n| GET | `/vms/{id}/guest-agent` | — |\n\n`POST /vms` takes the create options as `max_vcpus`, `max_memory_mib`,\n`firmware`, `secure_boot` and `tpm`.\n\n## See also\n\n- [Creating virtual machines](/docs/compute/virtual-machines)\n- [Lifecycle and restarts](/docs/compute/lifecycle)\n- [Current limits](/docs/compute/limits)\n"
        }
    ]
}