KVM tweaks for sophisticated setup

KVM tweaks for sophisticated setup

I want to deploy a minimal Whonix instance in the cloud.
I use a server with multiple cores. How can I optimize the KVM config files?
What should be changed?

What I want to change:

  1. No running GUI programs. I can this achieve by compiling Whonix KVM CLI, right?
  2. Increased disk space for my database (WS)
  3. Increased mount of cores (WS + GW). Does an increased amount of cores on the GW help with performance/stability? I know Tor is mostly single threaded.
  4. Increased amount of RAM (WS +GW). Does an increased amount of RAM on the GW help with performance/stability?

What can I do additionally for an sophisticated KVM setup?

Is it possible to use the folder host shared folder technique to store the database folder outside of Whonix? Would this be a performance problem?

Note: I don’t maintain Whonix KVM but I can answer a few build script specific questions.

The usual build documentation:

  • --flavor whonix-gateway-cli
  • --flavor whonix-workstation-cli

Might be Undocumented, Untested or Unsupported Features?

--vmsize 200G

as per:

Seems undocumented. This page is at time of writing for VirtualBox only.

Mostly unspecific to Whonix. Hence:

Never tried. Never heard. I suggest to make this a question unspecific to Whonix or just try.

You could contribute to this one:

Generic Bug Reproduction / research / contact upstream / enhance documentation.

I hope HolaHoop will answer my other questions too.

Sure a custom KVM cli build is feasible though I don;t provide one currently because of low demand.

You have up to 100GB though you can feel free to expand this using the QEMU disk utilities or you can add a second larger virtual disk and mount that inside the guest and place your db file there.

You need to remove CPU pinning if you want to see the effect of core increases. Tor’s performance has some design limitations, particularly when it comes to DoS resistance. As for hosting onions you need to take a look at onion balance for high perf deployments.

For normal desktop uses the current defaults cut it and going any further will just be a waste of resources. The current allocations should be reasonable on most user’s hardware. If you have more resources, you can always run multiple GW-WS pairs concurrently for multitasking.

Yes it should be possible and is recommended for backup purposes. It shouldn’t impact performance unless you have a very high rate of db queries. The throughput of file transfers is OK in my experience. report back if it isn’t.

[Imprint] [Privacy Policy] [Cookie Policy] [Terms of Use] [E-Sign Consent] [DMCA] [Contributors] [Investors] [Priority Support] [Professional Support]