A full-featured, self-hosted virtualization platform built on KVM/QEMU. Manage VMs, clusters, networking, storage, security, and compliance — all from a single dark-themed web UI. 114 enterprise capabilities: DRS, live migration, vTPM, confidential VMs, multi-tenancy, Terraform, Kubernetes CSI, Firecracker microVM, OPA policy engine, and more.
Everything you need to run production workloads.
Create, start, stop, reboot, clone, and snapshot VMs with full KVM power. Bulk operations, CPU pinning, vCPU hot-plug, scheduling, and template-based provisioning.
Browser-based VNC and serial console — no client needed. Pointer lock, Ctrl+Alt+Del, clipboard support, fullscreen, and SPICE for high-performance sessions.
Role-based access with four built-in roles: admin, operator, vm-user, and viewer. Assign specific VMs to tenants so they only see and manage what they own.
Automated VM configuration at first boot: SSH key injection, static IP setup, hostname assignment, and network configuration — no manual intervention required.
IP address management with CIDR pools, WireGuard VPN, VLAN tagging, SDN via Open vSwitch, HAProxy load balancer, per-VM QoS, and nftables firewall.
Built-in AI for natural-language VM creation, capacity forecasting, anomaly detection, and workload analysis. Predict resource exhaustion before it impacts production.
Distributed Resource Scheduler auto-balances VMs across hosts by CPU/RAM load. EVC CPU compatibility for live migration across CPU generations. Affinity/anti-affinity rules, NUMA-aware scheduling, maintenance mode evacuation.
vTPM 2.0 (Windows 11/BitLocker), AMD SEV/Intel TDX confidential VMs, LUKS2 disk encryption, automated CIS/NIST/PCI-DSS/HIPAA/ISO 27001 compliance scanner, DLP engine, forensics, SAML/OIDC SSO, MFA per role.
3-2-1 backup automation, app-consistent snapshots (fsfreeze), backup mount+boot verification, cross-site async/sync replication. RPO/RTO SLA tracking, automated DR runbooks, one-click failover.
Hard tenant isolation with per-tenant vCPU/RAM/disk quotas, self-service portal, chargeback/showback billing engine (€/$/TRY), 6-template service catalog, token-bucket rate limiting per tenant.
Kubernetes CSI driver (csi.oxware.io), OxwareVM CRD Operator, KubeVirt import/export, GitOps (ArgoCD/Flux), Pulumi IaC generation, workload mobility to AWS AMI / Azure VHD / GCP.
Firecracker microVM (125ms boot), Kata Containers runtime, WASM module execution (wasmtime/wasmedge), edge deployment mode. OPA/Rego policy-as-code, CloudEvents v1.0, workflow automation engine.
Official Terraform provider: oxware_vm, oxware_network, oxware_storage_pool resources + data sources. Full REST API (~190 endpoints) with OpenAPI spec auto-generated at /api/docs.
Full source on GitHub. No vendor lock-in, no subscriptions, no fees. Self-hosted on your own infrastructure forever. Community-driven development with enterprise features baked in.
v2.6.3 is complete — 114+ capabilities shipped. These are the features we're designing for the next major cycle.
Native clients — VM lifecycle, push alerts, live metrics, noVNC console snapshots, and quick actions on the go.
Multi-site cluster federation — manage multiple OXware nodes from a single global control plane with unified inventory and single-pane operations.
AMD SEV and Intel TDX hardware memory encryption. vTPM 2.0 + UEFI Secure Boot for untrusted-host environments.
Autonomous remediation — AI detects anomalies and triggers pre-approved runbooks without manual intervention.
Run OXware VMs as Kubernetes workloads. CSI driver for persistent volumes, Operator for lifecycle management.
Hard tenant isolation, per-tenant resource quotas, usage metering, and cost chargeback reports for MSP/hosting environments.
Per-VM Layer-7 firewall policies enforced via nftables/eBPF — east-west traffic control without external SDN hardware.
Electron-based desktop app for macOS, Windows, and Linux — native system tray, offline VM status, and local CLI integration.
One command and you're running.
# Install OXware (Ubuntu 22.04+ or Debian 12+, requires root) curl -sSL https://oxware.top/install.sh | sudo bash # Open the web UI after installation https://<server-ip>:8006 # complete the setup wizard on first boot
See how OXware stacks up against other hypervisor management platforms.
| Feature |
OXware
|
Proxmox VE | VMware ESXi | Virtualizor |
|---|---|---|---|---|
| License | MIT (free) | AGPL / paid sub | Commercial | Commercial |
| KVM / QEMU Backend | Proprietary | |||
| Web UI | Dark, modern SPA | |||
| REST API | Full | Partial | ||
| AI Assistant UNIQUE | ||||
| Built-in 2FA | Enterprise only | |||
| Live Migration | vMotion | |||
| OVA / VMDK Import | Auto UEFI detect | Limited | ||
| Auto TLS Cert | Let's Encrypt | |||
| IP Pool / IPAM | ||||
| Per-VM Firewall | iptables | |||
| Prometheus Metrics | Plugin only | |||
| LDAP / AD SSO | ||||
| WiseCP / WHMCS | 3rd party | Native | ||
| Self-Hosted | ||||
| BGP / SDN UNIQUE | NSX add-on |
Live commit history pulled from GitHub
Your feedback matters. Leave a quick review on Google to help grow the OXware community!
Write a Review on GoogleFollow our LinkedIn page for new features, releases, and announcements.
Follow on LinkedInAsk questions, share plugins, get help, and talk with other OXware users in real time.
Join DiscordSupport OXware by upvoting on Product Hunt. Every vote helps open source hypervisor management reach more people.
Upvote on Product Hunt