DEEN Download

Phillux

Virtualization platform for virtual machines and containers — from a single server to a small cluster with shared storage and live migration, managed through a web interface and a fully documented REST API.

Phillux dashboard: host, uptime, utilization and guest counts at a glance

Starts on one server, grows into a cluster

The simplicity of a single service, without giving up shared storage and live migration when you add a second host.

Runs without ballast One service, one file, one autostart. No cluster you must stand up first, no second database to maintain. On a single host, backing up means copying one file.
Windows 11 without detours UEFI, Secure Boot and a virtual TPM 2.0 are set up by Phillux itself. The installation runs unattended all the way to a finished desktop.
Faults stay caged The firewall hangs off each individual guest's network device, not off the host. A wrong rule takes at most that one guest off the network — never your own access.

Cluster & live migration

New: several Phillux hosts as one cluster — with shared storage a running machine moves between nodes without going down.

Cluster view: nodes with free CPU, RAM and disk, a suitability score, and the setup for shared storage and fencing

One control plane over every node

Join hosts with a single key and Phillux shows them side by side: how much CPU, memory and disk each still has free, and a suitability score so it can suggest the roomiest node when you create a new machine.

One node lays the configuration down, the others reconcile against it — and which node leads can be turned around at any time. On shared cluster storage (OCFS2) a running VM is live-migrated between nodes: the disk stays put, only the machine moves. A lock manager and fencing keep two nodes from ever writing over each other.

What a cluster needs

Product demos

List of virtual machines with status, OS, vCPU, RAM, disk and network

Manage virtual machines

Create, start, stop, snapshot, clone and back up. Each machine shows its firmware — create a Windows 11 guest and it gets UEFI, Secure Boot and TPM 2.0 automatically. Existing guests come across straight from VMware ESXi or Proxmox.

A real Phillux on a real machine — not a video, not a click-through mock-up. Sign in and look around; nothing is staged for you.

User
demo
Password
Demo187!

How a machine comes into being

Four tabs, then it runs. What Windows 11 demands is not a task in there — it is already set.

1The essentials
The “Basics” tab of the “Create a new VM” dialogue with name, vCPUs, RAM, disk, storage, network, operating system and firmware Name, vCPUs, memory, disk. Operating system and firmware sit side by side — choose Windows here and the firmware switches itself to UEFI.
2Where the system comes from
The “Source” tab offering an installation ISO, a prepared cloud image with cloud-init, or nothing at all for now From an installation ISO, from a prepared cloud image via cloud-init — or from nothing at all, if the ISO goes in later.
3What you rarely need
The “Hardware” tab with cores per socket, CPU limit and shares, CPU hot-add, disk controller, provisioning and limits for IOPS and MB/s Cores per socket, a hard CPU ceiling and shares for when the host is short, disk controller, thin provisioning, limits for IOPS and throughput. All of it has a sensible default.
4Firmware and boot
The “Hardware” tab further down: network adapter and MAC, chipset and Secure Boot, a note, and software RAID inside the guest Chipset and Secure Boot stand on “Automatic” — for Windows that means UEFI with Secure Boot active. Below it, the guest can be handed a software RAID of its own.

Compare editions

Licensed per server and year — Enterprise per 16 cores. What the software can do is the same in all three; only the size of the installation differs.

Essentials

For the single server that just needs to run a handful of machines reliably.

  • Virtual machines
  • LXC containers
  • Templates
  • Images & ISOs
  • Unattended installation
  • Snapshots
  • Cloning
  • Backups, with verification
  • Emergency brake against ransomware
  • Software RAID
  • Network storage (NFS, SMB, iSCSI)
  • Cluster storage (OCFS2, CephFS)
  • Custom virtual networks
  • Links between networks
  • Port forwarding
  • VLAN tags and fixed addresses
  • Network impairment
  • Per-guest firewall
  • Console and shell in the browser
  • Cluster & live migration
  • Labs and courses
  • Measurement history
  • Users and permissions
  • Publicly trusted certificates
  • Signed updates
  • Import from ESXi and Proxmox
  • Export to other hypervisors
  • USB and PCI passthrough
  • REST API and assistant (MCP)
Up to 1 socket · up to 8 cores
Cluster of up to 2 hosts
190 € per year
Buy
Recommended Standard

The usual fit: for the server that carries the daily load, with room up to two sockets.

  • Virtual machines
  • LXC containers
  • Templates
  • Images & ISOs
  • Unattended installation
  • Snapshots
  • Cloning
  • Backups, with verification
  • Emergency brake against ransomware
  • Software RAID
  • Network storage (NFS, SMB, iSCSI)
  • Cluster storage (OCFS2, CephFS)
  • Custom virtual networks
  • Links between networks
  • Port forwarding
  • VLAN tags and fixed addresses
  • Network impairment
  • Per-guest firewall
  • Console and shell in the browser
  • Cluster & live migration
  • Labs and courses
  • Measurement history
  • Users and permissions
  • Publicly trusted certificates
  • Signed updates
  • Import from ESXi and Proxmox
  • Export to other hypervisors
  • USB and PCI passthrough
  • REST API and assistant (MCP)
Up to 2 sockets · up to 16 cores each
Cluster of up to 4 hosts
390 € per year
Buy
Enterprise

For machines meant to grow: no ceiling on sockets, none on cores.

  • Virtual machines
  • LXC containers
  • Templates
  • Images & ISOs
  • Unattended installation
  • Snapshots
  • Cloning
  • Backups, with verification
  • Emergency brake against ransomware
  • Software RAID
  • Network storage (NFS, SMB, iSCSI)
  • Cluster storage (OCFS2, CephFS)
  • Custom virtual networks
  • Links between networks
  • Port forwarding
  • VLAN tags and fixed addresses
  • Network impairment
  • Per-guest firewall
  • Console and shell in the browser
  • Cluster & live migration
  • Labs and courses
  • Measurement history
  • Users and permissions
  • Publicly trusted certificates
  • Signed updates
  • Import from ESXi and Proxmox
  • Export to other hypervisors
  • USB and PCI passthrough
  • REST API and assistant (MCP)
Sockets, cores and cluster size without a ceiling
490 € per year for every 16 cores begun
Buy

Support, chosen separately

The software is the same in every edition, and answers by e-mail come with all of them. What can be bought in addition is a time we hold ourselves to — and how much of that you need is decided by what depends on the machine, not by how large it is.

Included 0 €

Answers by e-mail, without a promised time. In practice usually the same day, but nothing you could hold us to.

Business 290 € per year

An answer within one working day, guaranteed. For the server that something depends on.

Priority 690 € per year

An answer within four hours on working days, and we go through the move from ESXi or Proxmox with you.

Support is ordered together with the licence — say which level you want and it goes on the same invoice.

Which edition fits? The figures are ceilings, not requirements: an edition fits as long as you stay under all three, and whichever one you pass first decides the next edition up — a single socket with 12 cores is therefore Standard, not Essentials. Every edition can do everything, the cluster included — what the third figure limits is how many hosts may stand in one cluster, not what they may run. Each host carries a licence of its own. Essentials and Standard are one price for the whole server; Enterprise has no ceiling at all and is counted per 16 cores, each block begun, however its sockets are arranged. Prices in euro, and that is the amount you pay: no VAT is added, because we invoice under the Austrian small-business scheme (§ 6 (1) 27 UStG). A month of trying costs nothing and asks for no details.

What Phillux was built for

Images & ISOs: Debian netinst, virtio-win drivers and a Windows 11 image, all ready

Windows guests without firmware fiddling

Windows 11 demands UEFI, Secure Boot and a TPM 2.0. In Phillux that is not a checklist but the default: all three are there the moment you create a guest as Windows. The installation runs unattended to a finished desktop with an administrator account, and the matching drivers are already inserted.

More on Windows guests
Templates captured from a VM or container, ready to build new guests from

Provision from a template, or from a script

Capture a fully set-up VM or container once and build new guests out of it as often as you like. For Linux guests there is no install by hand at all: Phillux creates the machine from a ready image, sets user, password and access key, and starts it. And every button in the interface calls the same documented endpoint — what you can click, you can automate.

See the feature set
Firewall rules per guest, applied to each guest's network device

A firewall that can't lock you out

The rules hang off the network device of each guest, not off the host. A wrong rule can at worst take that one guest off the network — access to the server stays intact either way. A VM and a container with the same name are two different guests, each with rules of their own. The host's own ruleset is only shown, never changed.

See the feature set

Practice environments that build themselves

A lab is a description: machines, networks, wiring. Building it turns that into real guests.

The lab catalogue in Phillux with four exercises, each showing its guests, networks and the memory it needs

The same exercise, several times over

A lab can stand several times at once — every instance with a name prefix and a subnet of its own, so the participants never tread on each other. A reset puts an instance back to minute zero; a stage marks a point to come back to.

The catalogue holds ready-made setups: two segments with a link between them, a web server and database that install themselves, or a line with 300 ms of latency and 3 % packet loss — so it shows what an application really survives on a branch-office connection.

The lab editor with networks and their subnet, and guests with address, distribution and architecture

Exercises that mark themselves

A lab is not only machines but the exercise as well: steps with points, hints and a solution, checked automatically. An isolated lab deliberately has no way out to the internet — whatever the participants need is installed while it is built.

Several labs can be bundled into a course, and the results come out as a report. If the setup is needed elsewhere, export it and load it in over there.

The emergency brake against ransomware

Watches a guest from below — where malware inside the guest cannot see the watcher.

The emergency brake in Phillux with the sections “Watched machines” and “Incidents”

Halting, not killing

Phillux does not look inside the guest but at what is written underneath it: for a VM the blocks under its disk, for a container the files in its root file system. When too much of what was ordinary data a moment ago turns to noise, the machine is halted.

Halted, not shot dead — and that is the difference that counts. The guest notices nothing, the step can be undone, and the key of whatever is doing the encrypting is still sitting in the frozen memory. Because a false alarm costs nothing but a short pause, the brake is free to grab early instead of cautiously late.

Software RAID, on both levels

Several disks made into one — mirrored so a disk may fail, or striped with parity.

The storage page in Phillux with the “local” storage, the software RAID section and the rule for old snapshots

Under the storage — and inside the guest

On the host, several disks become one array, with a storage on top of it and therefore every VM that lives there. Before real disks go in, the whole thing can be rehearsed harmlessly on loop devices.

Independently of that, a guest can have a RAID of its own: extra disks are handed to the VM and it builds an mdadm array out of them at its first boot. One lies under the storage, the other inside the guest — and both at once is allowed.

See the feature set

Feature set

Virtual machines Create, start, stop, snapshot, clone and back up. Linux guests boot from a ready image, with no install by hand. Read more
Containers Templates for the common distributions, CPU and memory limits per container, a real terminal in the browser. Read more
Storage Several storages, separated by content type, each with its own default. Large uploads are streamed through and use no memory. Read more
Networks Your own networks with automatic addressing or a bridge onto the existing network. The host's network cards are only shown — never altered. Read more
Per-guest firewall Rules hang off each guest's network device. Phillux deliberately leaves the host's own ruleset alone — it is only shown. Read more
Cluster & live migration Several hosts as one cluster with a suitability score for placement, config reconcile, and live migration of a running VM over shared OCFS2 storage. Read more
Users and roles You sign in with the accounts that already exist on the server. Phillux stores no passwords; permissions are granted individually or by role. Read more
Encrypted connection Encrypted from the first start. A publicly trusted certificate is obtained by Phillux on request and adopted without a restart.
Background tasks Downloads, clones and backups keep running with progress and a log — even if you close the tab or sign out.
Signed updates Updates arrive as signed packages from your own update server and install cleanly — with a faithful rollback if one is ever needed.
Import from ESXi / Proxmox Bring existing guests across from VMware ESXi or Proxmox and keep running them under Phillux — disks, specs and network in one step. Read more
REST API Every function is a documented endpoint. The interactive documentation is generated from the program itself, so it cannot go stale. Read more

What else it does

The list above is what a hypervisor is expected to do. This is what grew out of running one.

The “Assistant connection (MCP)” panel with the endpoint address and the button that shows what the key may do
Assistant over MCP An assistant can create guests, wire networks together and read tasks over the Model Context Protocol — through the same endpoints and the same permission checks as a person. It can also look inside a guest without network, SSH or an account, so it checks what it built instead of reporting success and hoping. Read more
The “Link networks” dialogue with the two networks, the protocol and the option to rewrite the sender address
Links between networks Two virtual networks do not reach each other by themselves. A link opens the way in both directions — per direction and protocol if you want — and the sender address stays the guest’s own, so the firewall on the guest still applies. Read more
The backup page in Phillux with the search for a guest
Backups that get tested Whether a backup was any good is found out by restoring it, and that is exactly what nobody does. Phillux walks the round itself: restore under a name of its own, start it without a network card, ask something inside whether it answers, throw it away again. Three verdicts, kept apart: answered, ran, failed. Read more
The export panel of a VM with the targets on offer: OVA for VMware and VirtualBox, VMDK, qcow2, VDI, VHDX and a raw image
Export to another hypervisor A guest leaves as an OVA for VMware or VirtualBox, as qcow2 for Proxmox, as VHDX for Hyper-V, as VDI or as a raw image; a container as a rootfs tarball or an Incus/LXD image. Every target says what to do on the receiving side — an export nobody can bring in is worth nothing. Read more
The “New VM” dialogue with “Install without anybody answering it” ticked, and the fields for user, password and SSH keys
Unattended installation An installer ISO is measured, not recognised by its name: bootloader, kernel and command line are read off the image itself. Phillux then writes the answer file that this installer reads — or, where the ISO carries a finished system rather than an installer, copies that system onto the disk. Read more
The network impairment panel with delay, jitter, packet loss, cap, duplication and corruption
Network impairment Every lab network is faster and more reliable than any customer’s. Latency, jitter, packet loss, duplication, corruption and a rate cap can be set per guest, so an application meets the branch office on a satellite link here rather than there. Read more
The “Hand a port on” dialogue: port on the host, protocol, the guest it goes to and the port inside it
Port forwarding A guest in a NAT network has a way out but no way in. A forward hands a port of the host through to it, in a chain of its own that is written afresh at every change — nothing in the rest of the host’s ruleset is touched. Read more
The “DHCP addresses” tab: a reservation gives a MAC the same address every time, from outside and without getting into the guest
Fixed addresses and VLAN tags Which guest gets which address is settled from outside, as a DHCP reservation — which works for a machine still installing and for a Windows guest nobody has logged into yet. A VLAN tag sits on the guest’s own card, so no separate network has to exist first. Read more
The device list of a VM with a USB device and the warning that passing an input device through takes the host's own keyboard away
USB and PCI passthrough A USB device or a PCI card goes straight to a VM or a container. Most of the work is the checking: the disk the host boots from and the card your connection runs over are locked, and the IOMMU group is shown, because passing one device out of a group passes the whole group.
The history of a VM with CPU, memory, disk and network over a chosen period
Measurement history The live charts forget everything the moment you leave the page. The history does not: the host and every running guest are read out every few seconds and written down, so what the CPU did last Tuesday night has an answer.

System requirements

An ordinary server, no special hardware

Processorx86-64 with virtualizationThe virtualization extensions must be enabled in the BIOS — without them no guests can start.
Operating systemDebian 13For new hardware there is an installation medium that sets up Debian and Phillux unattended.
InstallationOne commandA script sets everything up, autostart and encrypted connection included. Phillux then runs as a service and survives every reboot.
MemorySum of the guests plus headroomPhillux itself needs little; your guests set the demand. Plan 8 GB for each Windows 11 guest.
StorageSized to the guestsMachines, installation media and backups can live on separate storages — SSD, hard disk and network storage mixed.
Cluster (optional)2+ nodes, shared storageA second host makes a cluster. Live migration additionally needs shared cluster storage (OCFS2) that every node can reach.
Your data stays on your server Phillux runs on your hardware, in your network. There is no cloud holding your machines, backups or credentials, and no telemetry about how you run it. The only thing that leaves is the periodic licence check — and if that ever fails to reach us, Phillux keeps working.

Frequently asked questions

|
What is Phillux?
A virtualization platform for your own servers: it manages virtual machines and containers along with storage, images, virtual networks, snapshots, clones, backups and a per-guest firewall. It runs on a single host or on several hosts as a cluster, operated through a web interface or directly over the REST API — both hit the same endpoints.
Can I run several servers as a cluster?
Yes. Join hosts with a single key and Phillux shows them side by side with the free CPU, memory and disk on each, plus a suitability score so it can place a new guest on the roomiest node. One node lays the configuration down and the others reconcile against it, and which node leads can be turned around at any time.
Can I live-migrate a running machine between nodes?
Yes, once the nodes share cluster storage (OCFS2) that each of them can reach. The disk file stays on the shared storage while only the running machine moves to another node — a lock manager and fencing make sure two nodes never write over each other. Without shared storage the cluster still balances placement, but a live move needs the shared disk.
Can I import VMs from VMware ESXi or Proxmox?
Yes. Point Phillux at an ESXi or Proxmox source and it brings the guest across — disks, specs and network — so you keep running it under Phillux. It's the same "New VM" flow, just starting from an existing machine instead of a blank one. Both are covered in full on the pages about the VMware alternative and the Proxmox alternative.
How do updates work?
Updates arrive as signed packages from your own update server, so nothing installs that wasn't signed with your key. An update replaces the code cleanly and restarts the service; if one ever needs undoing, the rollback restores the previous state faithfully rather than leaving a half-updated system behind.
Can I run Windows 11 as a guest?
Yes. Create a guest as Windows and it gets UEFI with Secure Boot active and a virtual TPM 2.0 automatically — exactly the three requirements Windows 11 otherwise trips over. The installation runs unattended and the matching drivers are inserted for you.
How do I sign in?
With an account that already exists on the server — the same credentials as for remote access. Phillux stores no passwords; the database only holds who may use it and with which role.
Does Phillux need an internet connection?
Not to run. If the licence temporarily can't be checked — because the server is offline, say — Phillux keeps working normally while a grace period runs. Pulling images and templates from the network of course needs a connection.
What does "unmanaged" mean for a network?
That the network already existed on the host before Phillux arrived. Phillux shows such networks and lets them start and stop, but takes no responsibility for how they were set up. Networks you create yourself are managed and fully editable.

Ready to start?

Try it fully for a month — no registration, and nothing held back.

Every topic on its own page

Fourteen pages, each written from what the program actually does — including where it stops.

Try free for a month — download it now