Who is this for?

This is an advanced topic for system administrators who want to enable users to run virtual machines (VMs) inside VMs.

What will you learn?

Upon completion of this Learning Path, you will be able to:

  • Start a VM on Linux using virsh.
  • Configure a host and guest VM to allow the guest VM to function as a hypervisor.
  • Use a standard benchmark suite to measure the performance impact of running software inside a nested VM against a regular guest VM and on bare metal.

Prerequisites

Before starting, you will need the following:

  • An Arm64 bare metal server with 64 cores or more, supporting FEAT_NV2 (available in Arm v8.4-A and later), with Fedora 44 installed

Summary

AI-assisted

This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.

Close
?
You’ll enable nested virtualization on a bare-metal Arm64 server and build a hypervisor that runs a guest VM. First, you’ll install virtualization tools and verify NV2 support on the host. You’ll then create a baseline guest VM, configure a second VM as a hypervisor, and boot a guest VM inside the hypervisor. Finally, you’ll pin CPU cores and compare sysbench throughput across the bare metal host and the guest VMs.

Frequently asked questions

AI-assisted

These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.

Close
?
Why do I need a bare-metal Arm64 server?
A bare-metal server provides direct access to the processor’s EL2 virtualization support and hardware that supports FEAT_NV2. A standard VM doesn’t provide the access needed to enable nested virtualization.
How do I confirm that nested virtualization is enabled on the host?
Check the host’s kernel messages for VHE+NV2 mode initialized successfully. If you see VHE mode initialized successfully without +NV2, nested virtualization isn’t enabled. Check whether the kernel argument was applied and whether the hardware supports FEAT_NV2.
How do I verify that the hypervisor VM can run a nested guest?
Inside the L1 hypervisor VM, check the kernel messages for CPU: All CPU(s) started at EL2 and confirm that /dev/kvm exists. These checks show that virtualization support is available to the VM.
How do I connect to the nested guest VM after it starts?
In the L1 hypervisor VM, use virsh net-dhcp-leases default to find the L2 guest’s IP address. Connect with ssh -i ~/guest_key fedora@<L2-guest-IP-address> using the private key that you copied into the hypervisor VM.
Which result should I compare across bare metal and guest VMs?
Compare events per second from your sysbench output to assess throughput. After pinning each system to the specified cores, calculate each guest’s overhead against your bare-metal result rather than treating the example numbers as expected results.
Next