Configure and run nested virtualization on an Arm server
Introduction
Prepare the host for nested virtualization
Prepare and start an L1 guest virtual machine
Create a hypervisor virtual machine on the host
Prepare and boot a nested L2 guest VM in the hypervisor VM
Benchmark Arm nested virtualization with sysbench
Next Steps
Configure and run nested virtualization on an Arm server
Who is this for?
This is an advanced topic for system administrators who want to enable users to run virtual machines (VMs) inside VMs.
What will you learn?
Upon completion of this Learning Path, you will be able to:
- Start a VM on Linux using virsh.
- Configure a host and guest VM to allow the guest VM to function as a hypervisor.
- Use a standard benchmark suite to measure the performance impact of running software inside a nested VM against a regular guest VM and on bare metal.
Prerequisites
Before starting, you will need the following:
- An Arm64 bare metal server with 64 cores or more, supporting FEAT_NV2 (available in Arm v8.4-A and later), with Fedora 44 installed
Summary
This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
You’ll enable nested virtualization on a bare-metal Arm64 server and build a hypervisor that runs a guest VM. First, you’ll install virtualization tools and verify NV2 support on the host. You’ll then create a baseline guest VM, configure a second VM as a hypervisor, and boot a guest VM inside the hypervisor. Finally, you’ll pin CPU cores and compare
sysbench throughput across the bare metal host and the guest VMs.Frequently asked questions
These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
A bare-metal server provides direct access to the processor’s EL2 virtualization support and hardware that supports
FEAT_NV2. A standard VM doesn’t provide the access needed to enable nested virtualization.Check the host’s kernel messages for
VHE+NV2 mode initialized successfully. If you see VHE mode initialized successfully without +NV2, nested virtualization isn’t enabled. Check whether the kernel argument was applied and whether the hardware supports FEAT_NV2.Inside the L1 hypervisor VM, check the kernel messages for
CPU: All CPU(s) started at EL2 and confirm that /dev/kvm exists. These checks show that virtualization support is available to the VM.In the L1 hypervisor VM, use
virsh net-dhcp-leases default to find the L2 guest’s IP address. Connect with ssh -i ~/guest_key fedora@<L2-guest-IP-address> using the private key that you copied into the hypervisor VM.Compare
events per second from your sysbench output to assess throughput. After pinning each system to the specified cores, calculate each guest’s overhead against your bare-metal result rather than treating the example numbers as expected results.