Full Virtualization vs Paravirtualization vs Hardware-Assisted Virtualization

Illustration comparing full virtualization, paravirtualization and hardware-assisted virtualization as three stacks

Paravirtualization is a technique where the guest operating system knows it runs in a virtual machine. It talks to the hypervisor directly, instead of acting as if it owns real hardware. Full virtualization runs an unmodified guest and hides the hypervisor from it. Hardware-assisted virtualization uses CPU features (Intel VT-x, AMD-V) to make full virtualization fast. Today most VMs use hardware assistance for the CPU and paravirtualized drivers, such as virtio, for disk and network.

Updated October 2026. This guide replaces the 2012 version with current tools and a home lab focus.

Who this is for: you run VMs in a home lab or a small team. You keep seeing terms like "PV", "HVM" and "virtio" in settings menus. You want to know what they mean and which to pick.

The problem these techniques solve

A hypervisor must stay in control of the real hardware. The guest OS kernel expects to control it too. So the hypervisor must catch every sensitive instruction the guest kernel runs, and handle it safely.

On many CPU designs, this is simple. A sensitive instruction run with too little privilege causes a trap, and the hypervisor steps in. The older x86 design did not work this way. The 2003 paper "Xen and the Art of Virtualization" from the University of Cambridge states the issue plainly. Support for full virtualization was never part of the x86 design. Some supervisor instructions fail silently when run without enough privilege, instead of causing a trap.

Three answers came out of that problem. Each one is still visible in the tools you use today.

Full virtualization with binary translation

Full virtualization means the guest OS runs unmodified. You install a stock copy of Windows or Linux, and it never learns it is in a VM. The hypervisor presents a complete virtual machine that looks like real hardware.

Before CPUs helped, x86 hypervisors did this in software. The Xen paper describes how VMware's ESX Server worked at the time. It rewrote parts of the guest's machine code on the fly to insert traps where the hypervisor had to step in. This is called binary translation. ESX Server also kept "shadow" copies of structures such as page tables, and trapped each attempt to change them.

The benefit is clear: any OS runs as it is. The cost is complexity and overhead. The hypervisor must translate guest kernel code. Work that updates page tables often, such as starting new processes, suffers the most.

What is paravirtualization?

Paravirtualization takes the opposite path. Instead of hiding the hypervisor, it changes the guest kernel so it cooperates. The guest calls the hypervisor directly (these calls are often named hypercalls) for privileged jobs such as page table updates. Nothing has to be caught or rewritten.

Xen made this approach well known. The 2003 Xen paper says paravirtualization was needed for high performance and strong isolation on x86. It also notes the price. The guest OS must be modified, but applications do not need to change, because the application binary interface stays the same. The Xen team ran a modified Linux (XenoLinux) and reported that a Windows XP port was in progress at the time.

That trade-off is the main weakness. VMware's 2007 white paper, "Understanding Full Virtualization, Paravirtualization, and Hardware Assist", names the problem. Paravirtualization needs guest OS changes, which make the guest depend on one specific hypervisor. Open-source kernels could be changed. Closed-source ones were harder.

Paravirtualization today: drivers, not kernels

Fully paravirtualized kernels are now uncommon. The idea lives on in a narrower form: paravirtualized devices. The guest uses a normal kernel, but it loads special drivers for disk, network and memory that know they talk to a hypervisor.

On KVM, QEMU and Proxmox, these drivers are called virtio. The Linux kernel documentation says virtio was first developed as a standard for paravirtualized devices that a hypervisor provides. The OASIS standards body publishes the specification. VIRTIO 1.0 was first approved as an OASIS Committee Specification in August 2014. You can read the VIRTIO 1.0 specification (the March 2016 revision). Newer versions exist, so check the OASIS site for the latest one.

Why it matters in a home lab: an emulated device copies the behavior of real hardware, such as an old Intel network card. That is slow, because the hypervisor must fake every register. A virtio device skips the act and uses a simple shared-memory channel. Linux guests include virtio drivers. Windows guests do not. The Proxmox wiki on Windows VirtIO drivers explains how to load them from the virtio-win ISO, as of October 2026.

Hardware-assisted virtualization

The third answer moved the hard part into the CPU. Intel added VT-x and AMD added AMD-V. These features give the hypervisor its own CPU mode. The guest kernel runs directly on the CPU, and the CPU itself hands control to the hypervisor when a sensitive event happens. No code rewriting and no guest changes are needed.

A second wave of features fixed memory overhead. Intel Extended Page Tables (EPT) and AMD Nested Page Tables (NPT, also called RVI) let the CPU translate guest memory addresses in hardware. The hypervisor no longer needs shadow page tables for every guest.

Hardware assistance is now the default. KVM, Hyper-V, current VMware products and VirtualBox all rely on it. Most of them will not start a 64-bit VM without it. If yours complains, read how to enable virtualization in BIOS.

The modern mix

Today the techniques are not rivals. A typical VM combines them:

  • CPU and memory: hardware-assisted (VT-x or AMD-V, with EPT or NPT).
  • Disk and network: paravirtualized (virtio, or the hypervisor's own equivalent).
  • Boot and legacy devices: emulated, for compatibility during install.

Xen shows the same shift. Its PVH guest type first appeared in Xen 4.4. The current design, PVH version 2, became a supported guest type in Xen 4.10. It uses hardware virtualization for the CPU and memory, paravirtualized drivers for I/O, and no QEMU device emulator. It mixes the best parts of the old PV and HVM modes.

Full virtualization vs paravirtualization: side by side

PointFull (binary translation)ParavirtualizationHardware-assisted
Guest OS changesNoneKernel or drivers modifiedNone
Needs CPU featuresNoNoYes (VT-x or AMD-V)
How sensitive work is caughtHypervisor rewrites guest codeGuest calls the hypervisorCPU traps to the hypervisor
Main costComplexity and overheadGuest tied to one hypervisorNeeds a modern CPU
Where you see it todayMostly historical on x86virtio and similar driversAlmost every VM

Two related techniques

OS-level virtualization

OS-level virtualization does not create virtual hardware at all. The host kernel splits itself into isolated user spaces. Containers (LXC, Docker, Podman) work this way. There is no guest kernel, so none of the three techniques above apply. For when to use one or the other, read containers vs virtual machines. For where this sits among all the other kinds, see the guide to types of virtualization.

Nested virtualization

Nested virtualization runs a hypervisor inside a VM. You might run Proxmox inside VirtualBox to learn it, or test Hyper-V inside a Hyper-V VM. The outer hypervisor must expose VT-x or AMD-V to the guest. Without that, the inner hypervisor falls back to slow emulation or refuses to start.

On Linux KVM, the kernel documentation on nested guests says nesting has been on by default since kernel 4.20. A distribution can override that. Nested VMs run slower than VMs on bare metal, so use them to learn and test, not for production. For the commands to check and enable it on Hyper-V, KVM and Proxmox, see how to enable virtualization.

What this means for your settings

You rarely pick a technique by name anymore. You pick device types. Here is a practical guide for KVM and Proxmox:

  • Linux guests: use VirtIO SCSI for disks and VirtIO for the network card. The drivers are already in the kernel.
  • Windows guests: attach the virtio-win ISO during install, load the storage driver, then switch the network to VirtIO.
  • Old or odd guests: use emulated devices (IDE or SATA disk, Intel E1000 network) if the OS has no virtio drivers.
  • CPU type: "host" passes the full CPU feature set to the VM. It is the simplest way to allow nested virtualization. A generic type helps when you plan to live-migrate VMs between different CPUs.

Common mistakes

  • Installing Windows on a VirtIO disk with no driver. The installer sees no disk. Load the driver from the virtio-win ISO first.
  • Leaving emulated devices in place after install. They work, but they waste CPU time. Switch to VirtIO once the drivers are in.
  • Thinking paravirtualization is obsolete. Full PV kernels are rare. PV drivers are everywhere.
  • Running a hypervisor in a VM without exposing VT-x or AMD-V. Set the CPU type and nesting first.
  • Calling containers "paravirtualization". Containers share the host kernel. They are OS-level virtualization.

For how the hypervisor assigns CPU, memory, disk and network to each VM, read what a hypervisor is, type 1 vs type 2.

FAQ

What is paravirtualization in simple terms?

It is a method where the guest OS knows it runs in a VM and asks the hypervisor for help directly. This avoids the work of catching and translating sensitive instructions. Today it mostly appears as paravirtualized drivers, such as virtio.

What is the difference between full virtualization and paravirtualization?

Full virtualization runs an unmodified guest that does not know it is virtual. Paravirtualization modifies the guest, or its drivers, so it cooperates with the hypervisor. Full virtualization runs any OS. Paravirtualization trades that freedom for less overhead.

Is KVM full virtualization or paravirtualization?

Both. KVM uses hardware-assisted full virtualization for the CPU and memory. It then uses virtio paravirtualized drivers for disk and network when the guest has them.

Is hardware-assisted virtualization the same as full virtualization?

It is a way to do full virtualization. The guest still runs unmodified. The difference is that the CPU, not software rewriting, catches the sensitive instructions.

Does Xen still use paravirtualization?

Xen still supports PV guests. It also offers HVM and PVH guests, which use hardware virtualization with PV drivers. Check the Xen Project docs for which modes your version supports.

Do containers use paravirtualization?

No. Containers share the host kernel and have no virtual hardware. They are a form of OS-level virtualization.

Related guides

Virtualization Software: Free and Paid Options Compared

Illustration of desktop and server virtualization software running virtual machines on a laptop and a server

Virtualization software lets one computer run many virtual machines (VMs). It comes in two groups. Desktop apps, such as VirtualBox, VMware Workstation and Parallels, run VMs on the computer you already use. Server platforms, such as Proxmox VE, VMware ESXi, Hyper-V and XCP-ng, turn a dedicated machine into a host for many VMs. Many good options are free as of October 2026.

Updated October 2026. This guide replaces the 2012 version with current tools and a home lab focus.

Who this is for: you want to run VMs at home or for a small team, and you need a short list of software to try.

Desktop vs server virtualization software

The first choice is not a brand. It is where the software runs.

  • Desktop apps (type 2 hypervisors) install on Windows, macOS or Linux like any other program. You use them for test VMs, a second OS or learning. Your VMs stop when you shut the laptop.
  • Server platforms (type 1 hypervisors) install directly on the hardware. The machine runs all day, and you manage it from a web browser or a console on another computer.

If the terms type 1 and type 2 are new, read what a hypervisor is and how the two types differ. Hyper-V is a special case. It is a type 1 hypervisor, but you can turn it on inside Windows 11 Pro.

Virtualization software comparison table

This table reflects vendor pages as of October 2026. License terms change often. Verify every row on the vendor's site before you decide.

SoftwareTypeRuns onLicense as of October 2026 (verify)Best for
VMware Workstation ProDesktopWindows, LinuxFree for all use, no paid supportPolished desktop VMs, VMware skills
VMware Fusion ProDesktopmacOSFree for all use, no paid supportMac users who want VMware
Oracle VirtualBoxDesktopWindows, macOS, LinuxOpen source (GPLv3); Extension Pack under separate licenseFree cross-platform lab
Parallels DesktopDesktopmacOSPaid (one-time or subscription by edition)Windows on a Mac, ease of use
UTMDesktopmacOSFree and open sourceFree VMs and emulation on a Mac
GNOME BoxesDesktopLinuxFree and open sourceSimple VMs on a Linux desktop
Hyper-V (client)Type 1, in WindowsWindows 10/11 Pro or EnterpriseIncluded with WindowsWindows users, WSL2 and Windows Sandbox users
Proxmox VEServerBare metal (x86)Open source (AGPLv3), optional subscriptionHome labs and small teams
VMware ESXi / vSphereServerBare metal (x86)Commercial subscription; limited free ESXi 8 editionTeams tied to the VMware ecosystem
Hyper-V (Windows Server)ServerBare metal (x86)Part of paid Windows ServerMicrosoft-based businesses
XCP-ngServerBare metal (x86)Open source, optional paid supportA Xen-based, VMware-like model
KVM with libvirtServerAny Linux hostOpen source, part of LinuxLinux admins who want full control
Nutanix Community EditionServerBare metal (x86)Free, community-supportedLearning Nutanix

Free virtualization software for your desktop

If you want to run VMs on the computer you own, start here. The VMware vs VirtualBox vs Proxmox comparison covers the top two in depth, with nested Proxmox steps. This section gives the short version and adds the others.

VMware Workstation Pro and Fusion Pro

Workstation Pro runs on Windows and Linux. Fusion Pro runs on macOS. On 11 November 2024, Broadcom made both free for commercial, educational and personal use. The paid versions are no longer sold. Free users get community forums and docs, not support tickets. Read the VMware announcement, then check the current download steps on Broadcom's site.

Oracle VirtualBox

VirtualBox runs on Windows, macOS and Linux. The base package is open source under the GNU GPL version 3. The Extension Pack is different. It is free for personal and educational use under the PUEL. Commercial use needs a paid enterprise license. See the VirtualBox licensing FAQ before you install the Extension Pack at work.

Hyper-V on Windows 11

Hyper-V is built into Windows 10 and Windows 11 Pro and Enterprise. There is nothing to download. You turn it on as a Windows feature. It cannot be installed on the Home editions. Your CPU needs Second Level Address Translation (SLAT). Microsoft lists 4 GB of memory as the minimum.

One warning. When the Hyper-V hypervisor runs, VMware Workstation and VirtualBox must run on top of it. They often run slower, and some features may not work. Microsoft's Hyper-V install guide warns that their VMs may not start or may run unreliably. Test your setup before you rely on it.

UTM and Parallels Desktop on a Mac

UTM is a free, open-source app for macOS built on QEMU. It can run VMs and can also emulate other CPU types, such as x86 Windows on an Apple Silicon Mac (slowly). Parallels Desktop is a paid app. As of October 2026, it comes in Standard, Pro and Business editions, with Standard sold as a one-time purchase and the others by subscription. Check the Parallels site for current prices.

GNOME Boxes on Linux

GNOME Boxes is a simple VM app for the GNOME desktop. It uses QEMU, KVM and libvirt underneath. You point it at an ISO, and it builds the VM with few questions. It suits quick tests. For more control on Linux, use virt-manager or a server platform.

Server virtualization software

A server platform needs its own machine. In return, your VMs run all day, and you get features such as snapshots, backups, clustering and live migration.

Proxmox VE

Proxmox VE is a Debian-based platform that runs KVM virtual machines and LXC containers from one web interface. As of October 2026, it is free and open source under the GNU AGPLv3. The full feature set works without a subscription. Paid subscriptions add the enterprise repository and, on most plans, technical support. See the Proxmox VE subscription page for the current plans.

For a home lab, this is the platform I would start with. Read what Proxmox VE is and why home labs run it for the full picture.

VMware ESXi and vSphere

ESXi is VMware's bare-metal hypervisor. vCenter manages many ESXi hosts together. As of October 2026, Broadcom sells vSphere as per-core subscription bundles. Get a current quote from Broadcom or a partner.

Free ESXi was withdrawn in February 2024. On 10 April 2025, Broadcom released ESXi 8.0 Update 3e as a free download from its support portal. Reported limits are 2 physical CPUs, 8 vCPUs per VM, no vCenter and no support. As of October 2026, no free ESXi 9 was found. For a full two-way comparison, read Proxmox vs VMware in 2026.

Microsoft Hyper-V on Windows Server

On a server, Hyper-V is a role you add to Windows Server. Microsoft Hyper-V Server 2019 was the last free, standalone Hyper-V product. On Windows Server 2025, Hyper-V comes with a paid Windows Server license. As of October 2026, Microsoft's Windows Server licensing says a fully licensed Standard host covers 2 Windows Server VMs. Datacenter covers unlimited Windows Server VMs. Licenses are per core. Check the current guidance with Microsoft or your reseller.

XCP-ng

XCP-ng is an open-source type 1 hypervisor based on Xen. Vates develops it, and the project is hosted by the Linux Foundation. You manage it with Xen Orchestra, a web tool for management and backups. Its model feels close to vSphere, with one management layer over many hosts. Vates sells support if you need it.

KVM with libvirt

KVM is the hypervisor built into the Linux kernel. Proxmox uses it, and so do many cloud providers. You can also use it directly on any Linux server, with libvirt to manage VMs and virt-manager or Cockpit as a front end. It is free and flexible. You build the parts that Proxmox gives you out of the box, such as backups and clustering.

XenServer (formerly Citrix Hypervisor)

XenServer (once called Citrix Hypervisor) is a commercial Xen-based platform. As of October 2026, it is licensed through Citrix subscriptions, and its branding has changed more than once. The guide to Hyper-V vs VMware vs Proxmox covers its history. Check the XenServer site for current editions and trial terms.

Nutanix Community Edition

Nutanix Community Edition (CE) is a free, community-supported version of the Nutanix platform with the AHV hypervisor. It is a good way to learn Nutanix if your employer uses it. As of October 2026, it needs a free Nutanix account to download, and much more memory and disk than Proxmox. Read the Nutanix CE getting-started guide for current requirements before you try it.

How to choose virtualization software

Answer these questions in order.

  1. Do you need VMs only while you work at your computer? Use a desktop app. VirtualBox is free everywhere. VMware Workstation or Fusion is free and polished. On a Mac, also look at UTM and Parallels.
  2. Do you run Windows Pro and use WSL2 or Windows Sandbox? Hyper-V is already there. Use it to avoid clashes.
  3. Do you want services that run all day? Use a server platform on a spare PC or mini PC. Proxmox VE is the easiest start for most home labs.
  4. Is your workplace on VMware, Hyper-V or Nutanix? Learn that platform, nested or on spare hardware, for job skills.
  5. Are you a small business choosing a platform? Read the side-by-side of Hyper-V vs VMware vs Proxmox before you buy.

What to watch for

  • Old license advice. VMware, VirtualBox and Citrix terms changed in 2024 to 2026. Read the vendor page, not a forum post (or this one) as the final word.
  • Two hypervisors on one PC. Hyper-V, WSL2 and some Windows security features take over the CPU's virtualization features. Other desktop apps then run slower or fail.
  • Hardware support. ESXi has a strict hardware list. Proxmox and KVM follow Linux drivers. Check network cards and storage controllers before you buy.
  • The Extension Pack at work. The VirtualBox base package is free for any use. The Extension Pack is not free for commercial use.
  • Apple Silicon. An M-series Mac runs ARM guests at near-native speed. x86 guests need emulation, which is slow.

FAQ

What is the best free virtualization software?

For a desktop, VirtualBox and VMware Workstation Pro are both free as of October 2026. For a dedicated server, Proxmox VE is free with every feature. The best one depends on whether you need VMs on your own computer or on a separate host.

Which virtualization software is free for commercial use?

As of October 2026, VMware Workstation Pro and Fusion Pro, the VirtualBox base package, Proxmox VE, XCP-ng and KVM are free for commercial use. The VirtualBox Extension Pack and Parallels Desktop are not. Verify each license on the vendor's site before you use it at work.

Which virtualization software runs on Linux?

On a Linux desktop, use VirtualBox, VMware Workstation Pro, GNOME Boxes or virt-manager. On a Linux server, KVM with libvirt is built in, and Proxmox VE is a full platform built on Debian. All of these are free as of October 2026.

Which virtualization software is best for a Mac?

On Apple Silicon, VMware Fusion Pro and UTM are free, and Parallels Desktop is a paid option. All three run ARM guests well. Proxmox VE does not run on a Mac, so learn it on a spare x86 PC.

Can I run virtualization software on a laptop?

Yes. Any desktop app in this guide runs on a modern laptop with hardware virtualization turned on. Memory is the usual limit, so check what each VM needs. For VMs that run all day, use a server platform on a separate machine.

Related guides

Hermes vs OpenClaw on Virtual Machines: Which Fits Your Setup?

Illustration comparing two AI agents running in identical virtual machines on the same server

Hermes vs OpenClaw comes down to what you want the agent to be. Hermes Agent, from Nous Research, is a self-improving agent that writes its own skills and keeps memory, with a terminal UI and a messaging gateway. OpenClaw is a personal assistant built around one gateway that connects to about 30 chat channels and a public skill registry. Both are MIT-licensed, both officially support Linux, and both need the same care: keep them off the open internet and snapshot before every update.

Who this is for: you want to self-host one AI agent in a home lab or on a VPS, and you want to know which one to set up first.

How this comparison works: it compares both agents from each project's official docs and repo as of 9 October 2026. Lab measurements will follow on the VM spec below. Until then, you see a placeholder where a measured number belongs. I do not print numbers I have not measured.

Hermes vs OpenClaw at a glance

Every product fact below is as of October 2026. Both projects ship often, so verify each one in the Hermes Agent docs and the OpenClaw docs before you rely on it.

FactorHermes AgentOpenClaw
MakerNous ResearchOpenClaw Foundation (created by Peter Steinberger)
LicenseMITMIT
Latest stable (8 Oct 2026)v0.21.62026.9.9
Core ideaAgent that learns: memory, self-written skills, scheduled tasksPersonal assistant across chat apps, with a skill registry (ClawHub)
Native installOfficial install script with pinned Python and Node.jsOfficial install script or npm; Node.js 24.16+ or 26.1+
Docker imagenousresearch/hermes-agentghcr.io/openclaw/openclaw
Docker setupdocker run or a short compose fileRepo checkout plus setup.sh and Docker Compose
Main ports8642 (API, off by default), 9119 (dashboard)18789 (dashboard and WebSocket)
Default bind, native install127.0.0.1Loopback
Default bind, in DockerDashboard on 0.0.0.0Gateway on the LAN
Run as a servicehermes gateway install (systemd)openclaw gateway install (systemd)
Updatehermes update --backup; new image in Dockeropenclaw update; new image tag in Docker
Built-in backuphermes backup / hermes importopenclaw backup create --verify
Local modelsYes (llama.cpp or Ollama); needs 64,000+ tokens of contextYes (managed llama.cpp, Ollama, LM Studio and more)
Published GitHub advisories (9 Oct 2026)None listed722, each with a patched version listed

The advisory count needs context. OpenClaw grew very fast in early 2026 and drew heavy security research. A long advisory list shows scrutiny and fixes, not only risk. An empty list does not prove that Hermes has fewer flaws. It may have had less scrutiny so far.

The planned test VM

Both agents will get the same VM spec, matching the install guides on this site.

SettingValue
OSUbuntu Server 24.04 LTS
vCPUs / RAM / disk2 / 4 GB / 32 GB
NetworkNAT, no inbound ports
Hermes installOfficial script, systemd user service
OpenClaw installDocker Compose, pinned pre-built image, gateway port bound to localhost
ModelThe same cloud model for both

The full steps are in two companion guides: install Hermes Agent on an Ubuntu VM and install OpenClaw in an Ubuntu VM with Docker Compose.

Install and setup

Hermes installs with one script. It brings its own pinned Python and Node.js, so it does not clash with what is on the VM. Setup is a few commands: hermes model, hermes tools and, for chat apps, hermes gateway setup. As of October 2026, pip and Homebrew installs are not supported.

OpenClaw also has a one-line installer that installs Node.js if needed and starts onboarding. Its Docker route has more parts. You clone the repo, run setup.sh, and manage a Compose stack with a gateway service and a CLI service. The compose file publishes three ports on all interfaces by default, so you should edit it before first start.

For a first-time self-hoster, Hermes asks for fewer decisions up front. OpenClaw's Docker route gives more control but needs more care.

Security defaults

Both projects are honest about risk. Neither one claims to contain a misbehaving model on its own.

  • Hermes says the operating system is the only real security boundary. By default, its local terminal backend runs commands on the host with no isolation. Dangerous commands need approval, and the gateway denies every chat user who is not on an allowlist or paired.
  • OpenClaw says sandboxing is off by default and is "not a perfect security boundary" when on. It ships a security audit command and a documented hardened baseline. Its docs state that container images default to an exposed bind, which they pair with required token auth.

The skill supply chain needs care on both. OpenClaw has ClawHub, a public registry of community skills. In early 2026, researchers found hundreds of malicious skills there. OpenClaw responded with VirusTotal scanning, but its own announcement says a clean scan does not mean a skill is safe. Hermes also writes skills from your use, but its Skills Hub can install community skills from registries, ClawHub included, after a security scan. On either agent, read a third-party skill before you install it.

For both, the VM is what turns "the agent ran a bad command" into "I reverted a snapshot". The post on disadvantages of server virtualization covers the limits of VM isolation too.

Ports and remote access

Neither agent needs an inbound port for chat apps. Telegram, Discord and the rest work over outbound connections. You only need a port to reach the web dashboard.

For both, the safe pattern is the same. Keep the dashboard on the VM's localhost and open an SSH tunnel from your own computer. Hermes uses port 9119 for its dashboard. OpenClaw uses port 18789. Never forward either port on your router. On 31 January 2026, Censys counted 21,639 OpenClaw instances exposed on the internet, and most still asked for a token. "Most" is not good enough.

Updates and recovery

This is where a VM pays for itself.

TaskHermes AgentOpenClaw
Updatehermes update --backupopenclaw update --dry-run, then openclaw update
Pin a versionDocker image tagopenclaw update --tag or a Docker image tag
Where state lives~/.hermes/~/.openclaw plus an auth-profile secrets folder
Rollback warningDo not delete the data folder to repair an installDowngrading does not reverse config or database changes
Best rollbackVM snapshotVM snapshot

Both store state in SQLite, and both backups contain credentials. Encrypt them. With Hermes, do not put the data folder on a hypervisor shared folder, because the docs warn that some cross-VM mounts can corrupt the database.

Which one fits your setup?

Choose Hermes Agent if

  • You want an agent that runs tasks, remembers context and improves its own skills over time.
  • You prefer a single install script and a simple systemd service.
  • You want an agent that writes most of its own skills, and you will install third-party skills only after you read them.

Choose OpenClaw if

  • You want one assistant across many chat apps, including WhatsApp, Signal and Microsoft Teams. (iMessage needs a Mac, so it does not fit a Linux-only VM.)
  • You want ready-made community skills and accept the duty to read them first.
  • You are comfortable with Docker Compose and a few security settings.

Can you run both?

Yes, but give each its own VM. OpenClaw's docs say to keep one trust boundary per gateway. Two small VMs also mean two separate snapshot histories, so a bad update to one never touches the other. A home lab makes this cheap. See what a home lab is for ways to start with hardware you already own.

Home VM or VPS?

Both agents run on a small VPS. The OpenClaw docs include guides for several VPS providers, and the Hermes README mentions a $5 VPS. A VPS runs around the clock without a spare PC. A home VM costs nothing extra and keeps your data at home. The rules do not change: an SSH-only firewall, no public dashboard port, and snapshots or backups before updates. If you want an always-on box at home, the home server setup guide covers the hardware.

FAQ

Is Hermes better than OpenClaw?

Neither is better for everyone. Hermes suits people who want a learning agent with a simple install. OpenClaw suits people who want one assistant across many chat apps. Try both in separate VMs for a week and keep the one you use.

Are Hermes Agent and OpenClaw free?

Both are open source under the MIT license. You pay for the model you connect, unless you run a local model. A VPS, if you use one, has its own cost.

Can Hermes and OpenClaw use local models?

Yes. Both can use llama.cpp or Ollama. Hermes rejects models with less than 64,000 tokens of context, so raise Ollama's default. Local models need much more RAM than the agents themselves.

Which is safer to self-host?

Neither is safe by default on the open internet. Both can install community skills, so read each one first. OpenClaw has more published fixes and a security audit command. In both cases, a VM, localhost-only ports and snapshots do most of the work.

Do I need Docker for either one?

No. Both have native installers and official Docker images. Docker gives you pinned versions and easy rebuilds. A VM gives you stronger isolation and snapshots. The guide to containers vs virtual machines explains the trade-off.

Related guides

Install OpenClaw in an Ubuntu VM with Docker Compose

Illustration of an AI agent running in Docker containers inside a virtual machine, with a locked network port

This OpenClaw Docker guide runs the agent inside an Ubuntu VM. Install Docker Engine with the Compose plugin, and clone the OpenClaw repo. Then run the official setup script with a pinned pre-built image. The script asks for your model API key, creates a gateway token and starts the stack. Before you use it, bind the dashboard port to localhost and reach it over an SSH tunnel.

Who this is for: you want to try OpenClaw, the open-source personal AI agent (once called Clawdbot and Moltbot), in a setup you can throw away and rebuild.

Why a VM and Docker, not your main computer

OpenClaw connects a language model to your chat apps, your files and a shell. That power is the point, and it is also the risk. On 31 January 2026, Censys counted 21,639 OpenClaw instances reachable on the internet. In early February, security researchers reported hundreds of malicious skills on ClawHub, the public skill registry. As of 9 October 2026, the project's GitHub page lists more than 700 security advisories, most of them fixed.

None of that means "do not use it". It means "do not run it next to your personal data". Two layers help:

  • The VM gives OpenClaw its own operating system, kernel and disk. Your laptop is out of reach, and snapshots let you undo anything.
  • Docker inside the VM gives you a pinned image, a clear list of data folders and a one-command rebuild.

Docker alone shares the host kernel, so it isolates less than a VM. The guide to containers vs virtual machines explains the difference. Here you get both.

What you need

  • A hypervisor. Proxmox VE on a spare PC, VMware Workstation or Fusion, or VirtualBox. See VMware vs VirtualBox vs Proxmox if you have not picked one. As of October 2026, OpenClaw publishes images for AMD64 and ARM64, so an ARM Ubuntu VM on an Apple Silicon Mac is a valid target.
  • Ubuntu Server 24.04 LTS. The OpenClaw docs say Linux is fully supported and give Ubuntu setup steps. As of October 2026, they do not publish a tested list of distribution versions.
  • A model. An API key from a provider such as Anthropic, OpenAI or OpenRouter, or a local model server such as Ollama.

VM size

OpenClaw publishes no general minimum for a Linux server. Its Raspberry Pi page states 1 GB of RAM, 1 core and 500 MB of disk as a floor. Building the Docker image from source needs at least 6 GB of RAM, but a pre-built image avoids that. The sizes below are my suggestion for a comfortable lab VM, not an official figure.

ResourceSuggestedNote
vCPUs2One is enough to start
RAM4 GBUse the pre-built image. A source build needs 6 GB or more.
Disk32 GBOS, Docker images, workspace and snapshots
NetworkNATOpenClaw needs outbound access only

Step 1: Create the VM and install Docker

Create the VM, install Ubuntu Server with the OpenSSH server, and log in as your normal user. Update the system:

sudo apt update && sudo apt upgrade -y
sudo apt install -y git

Install Docker Engine and the Compose plugin with the steps on the Docker Engine install page for Ubuntu. Use Docker's own repository, not the older docker.io package, so you get Compose v2. Check both tools:

docker --version
docker compose version

Shut down the VM and take a snapshot called docker-ready. This is your clean return point.

Step 2: Get the OpenClaw Docker Compose files

The Docker setup runs from a checkout of the official repo:

git clone https://github.com/openclaw/openclaw.git
cd openclaw

Pick a version and pin it. As of 8 October 2026, the latest stable release was 2026.9.9. Check the releases page for the current one, and use that tag in place of latest:

export OPENCLAW_IMAGE="ghcr.io/openclaw/openclaw:2026.9.9"

A pinned tag means the agent does not change under you when you restart. Only download images from ghcr.io/openclaw/openclaw or the openclaw/openclaw Docker Hub mirror. The docs warn against unofficial mirrors.

Step 3: Close the ports before first start

This step is not in the quick start, and it matters. Open docker-compose.yml and find the ports: block of the openclaw-gateway service. As of October 2026, it publishes three ports on every network interface:

    ports:
      - "${OPENCLAW_GATEWAY_PORT:-18789}:18789"
      - "${OPENCLAW_BRIDGE_PORT:-18790}:18790"
      - "${OPENCLAW_MSTEAMS_PORT:-3978}:3978"

Port 18789 serves the dashboard and the WebSocket API. Port 3978 is for Microsoft Teams. The old bridge on port 18790 is gone. Current builds use 18790 only if you turn on MCP Apps. If you do, add a second localhost line for it and tunnel it too. Change the block so the gateway listens on the VM's localhost only, and drop the ports you do not use:

    ports:
      - "127.0.0.1:${OPENCLAW_GATEWAY_PORT:-18789}:18789"

Why edit the file? The container binds the gateway to the LAN by default, and the OpenClaw security docs say so plainly. Also, ports that Docker publishes skip the host's normal firewall rules, so UFW alone does not protect them. The gateway still requires a token, but a closed port is a stronger default. Keep a note of this change, because git pull may conflict with it later.

Step 4: Run the setup script

From the repo folder, run the official script:

./scripts/docker/setup.sh

With OPENCLAW_IMAGE set, the script pulls the pre-built image instead of building one. It then asks for your model provider's API key, writes a gateway token to .env and starts the gateway with Docker Compose. The full flow is on the OpenClaw Docker page.

Check that the stack is up:

docker compose ps
docker compose logs -f openclaw-gateway

Step 5: Open the dashboard over an SSH tunnel

From your own computer, open a tunnel to the VM:

ssh -N -L 18789:127.0.0.1:18789 you@vm-address

Keep local port 18789. The setup script allows only that origin for the dashboard.

Then, in the VM, print the dashboard link:

docker compose run --rm openclaw-cli dashboard --no-open

Open the link in your browser. If the page says pairing required or unauthorized, approve your browser as a device:

docker compose run --rm openclaw-cli devices list
docker compose run --rm openclaw-cli devices approve <requestId>

Add a chat channel (optional)

The docs suggest Telegram first, because it needs only a bot token. Run the CLI through Compose:

docker compose run --rm openclaw-cli channels add --channel telegram --token <bot-token>

Start the line with a space, or clear it from your shell history afterwards, so the token is not saved. Unknown senders get a pairing code by default. Leave that on.

Step 6: Harden the install

  • Run the audit. docker compose run --rm openclaw-cli security audit checks your config against the safe defaults.
  • Treat skills as untrusted code. The docs say to read a skill before you enable it. A clean ClawHub scan does not prove a skill is safe.
  • Tighten tools with the hardened baseline. The OpenClaw security docs list it. It denies shell commands, limits file access to the workspace and turns off elevated tools. In Docker, copy only its tools and channels settings. Leave gateway.bind as lan and keep the token that setup created. A loopback bind inside the container makes the dashboard unreachable.
  • Keep secrets out of the VM. Do not sign the agent into accounts it does not need.
  • Leave the Docker socket mount off. It is commented out in the compose file. Mounting it gives the container control of Docker on the VM.

Snapshots, backups and rollback

OpenClaw keeps its state in three folders on the VM, mounted into the container:

  • ~/.openclaw: config, the .env file and the SQLite databases
  • ~/.openclaw/workspace: the agent's working files
  • ~/.openclaw-auth-profile-secrets: auth profile secrets

The docs warn that OAuth tokens sit in plain text in SQLite under the config folder. Treat every copy of these folders as a password vault.

Also, never copy live .sqlite, -wal or -shm files. Stop the stack first:

docker compose down
sudo tar czf ~/openclaw-backup-$(date +%F).tar.gz ~/.openclaw ~/.openclaw-auth-profile-secrets ~/openclaw/.env ~/openclaw/docker-compose.yml
docker compose up -d openclaw-gateway

The repo's .env holds the image pin and the gateway token, so the archive is a secret. Encrypt it before it leaves the VM.

A safe upgrade routine

  1. Take a VM snapshot.
  2. In the repo folder, edit .env and set OPENCLAW_IMAGE to the new version tag.
  3. Run docker compose pull openclaw-gateway openclaw-cli.
  4. Run docker compose up -d openclaw-gateway.
  5. Test one simple task.
  6. If it fails, revert the snapshot. Do not just switch the tag back, because the new version may have migrated the database.

On start, the image runs openclaw doctor --fix and saves SQLite backups ending in .pre-startup-migration-<id>.bak. Still, the docs say a downgrade does not reverse config or database changes. That is why the VM snapshot is your real rollback.

Troubleshooting

SymptomFix
EACCES on /home/node/.openclawThe image runs as user ID 1000. Run sudo chown -R 1000:1000 ~/.openclaw ~/.openclaw-auth-profile-secrets.
Build killed, exit code 137Out of memory. Use a pre-built image with OPENCLAW_IMAGE.
pairing required or disconnected (1008)Run devices list, then devices approve, as in step 5.
origin not allowedAdd your dashboard URL to gateway.controlUi.allowedOrigins.
EADDRINUSEAnother gateway uses the port. Stop it or change OPENCLAW_GATEWAY_PORT.
Config change has no effectdocker compose restart does not reload env changes. Run docker compose up -d openclaw-gateway.
Skill fails with brew not installedThe image has no Homebrew. Build a local image with OPENCLAW_IMAGE_APT_PACKAGES set (a source build needs 6 GB of RAM), or build your own image on top of the official one.

For anything else, run docker compose run --rm openclaw-cli doctor --json and read the findings. If that does not fix it, revert the snapshot and start again.

Docker or the native install?

OpenClaw also has a one-line native installer that sets up Node.js and a systemd service. On a host install, the gateway binds to loopback by default. The Docker route gives you a pinned image and easy rebuilds. The native route gives you openclaw update and fewer moving parts. In a VM, both are fine. If you also want to try Hermes Agent, read the Hermes Agent Ubuntu VM guide, then the Hermes vs OpenClaw comparison.

FAQ

What port does OpenClaw use?

The gateway uses port 18789 for the dashboard and the WebSocket API. As of October 2026, the compose file also publishes 18790 and 3978 (Microsoft Teams). Bind 18789 to localhost and reach it with an SSH tunnel or Tailscale.

How much RAM does OpenClaw need in Docker?

A pre-built image runs in far less than a source build. The docs say a source build needs at least 6 GB of RAM. For a lab VM, 4 GB with a pre-built image is a comfortable start.

Is OpenClaw safe to run?

It is as safe as your setup. Keep the gateway off the public internet, use token auth, read every skill before you enable it, and keep personal accounts out of it. A VM with snapshots limits the damage if something goes wrong.

Is a VPS better than a home VM for OpenClaw?

A VPS runs around the clock and needs no hardware at home. A home VM keeps your data on your own machine and costs nothing extra. On either, use an SSH-only firewall and never expose the gateway port directly.

Can I run OpenClaw on Proxmox?

Yes. Create an Ubuntu VM on Proxmox and follow this guide. As of October 2026, OpenClaw has no official Proxmox page, so treat the VM as any Linux Docker host. See what Proxmox VE is if you are new to it.

How do I update OpenClaw in Docker?

Take a snapshot, set the new tag in the repo's .env file, run docker compose pull, then docker compose up -d openclaw-gateway. Avoid latest, so you know which version you run.

Related guides

Install Hermes Agent on an Ubuntu Virtual Machine: Setup, Snapshots, and Recovery

Illustration of an AI agent running safely inside an Ubuntu virtual machine, with snapshot and rollback symbols

A Hermes Agent install on an Ubuntu virtual machine takes four steps. Create an Ubuntu 24.04 VM, install a few packages, and run the official install script. Then choose a model provider with hermes model and run the gateway as a systemd service. Take a VM snapshot before the install and another after it works. If an update or the agent itself breaks something, you revert the snapshot and start again.

Who this is for: you want to try Hermes Agent, the open-source AI agent from Nous Research, without giving it access to your main computer.

Why run Hermes Agent in a virtual machine

Hermes Agent is not a chatbot in a browser tab. It runs shell commands, edits files, keeps memory and can act on a schedule. By default it runs those commands directly on the machine where you install it. The project's own security policy is blunt about this. It says, "The only security boundary against an adversarial LLM is the operating system."

A virtual machine gives the agent its own operating system. If it deletes the wrong folder or installs something odd, the damage stays inside the VM. Your laptop, your photos and your saved browser logins are not in reach. The security docs also suggest a separate machine or VM for maximum isolation. If you want the background on why a VM isolates more than a container, read containers vs virtual machines.

A VM also gives you snapshots. A snapshot saves the whole machine at one point in time. That is the best recovery tool you have for an agent that changes its own environment.

What you need

A hypervisor

Any desktop or server hypervisor works. If you are not sure what that word means, read what a hypervisor is first. Common choices:

  • Proxmox VE on a spare PC or mini PC. Good if the agent should run around the clock. See what Proxmox VE is.
  • VMware Workstation Pro or Fusion Pro on your desktop. As of October 2026, both are free for all use. Verify this on the Broadcom site.
  • VirtualBox on Windows, Linux or macOS (check that your version supports your Mac's chip).

The guide to VMware vs VirtualBox vs Proxmox compares them for a desktop lab. On an Apple Silicon Mac, use an ARM build of Ubuntu in VMware Fusion. As of October 2026, the Hermes platform page lists Linux on both x86_64 and aarch64 as supported.

VM size

Nous Research publishes resource figures only for the Docker container. As of October 2026, those are 1 GB of RAM minimum and 2 to 4 GB recommended, 1 CPU core minimum and 2 recommended. Browser tools need at least 2 GB of RAM. A full VM also needs room for Ubuntu itself, so I suggest the sizes below. They are my suggestion, not an official figure.

ResourceSuggested VM sizeWhy
vCPUs2Matches the recommended container figure
RAM4 GBUbuntu plus the agent plus browser tools
Disk32 GBOS, runtimes, logs, sessions and snapshot headroom
NetworkNAT or bridgedThe agent needs outbound internet only
GPUNoneOnly needed if you run a local model

A model provider

Hermes Agent needs a language model. You can use a cloud provider such as OpenRouter, Anthropic, OpenAI or Nous Portal, with an API key. You can also run a local model through llama.cpp or Ollama. Note one hard rule: Hermes rejects models with less than 64,000 tokens of context. Ollama's default context is lower, so you must raise it. Check the providers page for the current list.

Step 1: Create the Ubuntu VM

Download Ubuntu Server 24.04 LTS from the Ubuntu website. Create a VM with the sizes above and install Ubuntu with default options. Turn on the OpenSSH server during setup so you can work from your own terminal.

Use Ubuntu 24.04. The Hermes docs say they test on the latest Ubuntu. As of October 2026, I found no official statement that Ubuntu 22.04 is tested.

Step 2: Prepare Ubuntu

Log in over SSH as your normal user, not root. Update the system and install the prerequisites:

sudo apt update && sudo apt upgrade -y
sudo apt install -y git curl tar libatomic1

The installer needs Git, curl, tar and SHA-256 tools. Ubuntu ships the SHA-256 tools already. The libatomic1 package is there for a reason. Early installs on minimal Ubuntu 24.04 images failed silently without it. The current installer adds it for you, but installing it first costs nothing.

Step 3: Take a clean snapshot

Shut down the VM and take a snapshot. Name it something plain, such as clean-ubuntu. This is your return point if the install goes wrong.

  • Proxmox: select the VM, open Snapshots, click Take Snapshot.
  • VMware: VM menu, Snapshot, Take Snapshot.
  • VirtualBox: Machine Tools, Snapshots, Take.

Step 4: Run the Hermes Agent install script

Start the VM and run the official one-line installer from the Hermes installation docs:

curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash

Read any script before you pipe it to bash. You can download it first with curl -fsSL https://hermes-agent.nousresearch.com/install.sh -o install.sh, read it, then run bash install.sh.

The script brings its own pinned Python and Node.js runtimes. It does not use your system Node.js. As of October 2026, pip, PyPI and Homebrew installs are not supported, so use the script. When it finishes, reload your shell and start the agent:

source ~/.bashrc
hermes

Here is where the files go:

  • Code: ~/.hermes/hermes-agent/
  • Launcher: ~/.local/bin/hermes
  • Data: ~/.hermes/, including config.yaml, .env (your API keys), memories, skills, sessions and state.db

Step 5: Choose a model and tools

Run the setup commands. You can do them one at a time or run the full wizard with hermes setup.

hermes model          # choose your provider and model
hermes tools          # choose which tools the agent may use
hermes config get     # check a setting

Start with few tools. Lock down the key file at the same time:

chmod 600 ~/.hermes/.env

Step 6: Run Hermes as a service

To keep the agent running after you log out, install the gateway as a systemd user service. Then turn on lingering so the service starts at boot without a login:

hermes gateway install
hermes gateway start
hermes gateway status
sudo loginctl enable-linger $USER

View the logs with journalctl --user -u hermes-gateway -f or hermes logs gateway -f.

Connect a chat app (optional)

The gateway can talk to you through Telegram, Discord, Slack, Signal, email and others. Run hermes gateway setup and follow the prompts. As of October 2026, the gateway denies every user who is not on an allowlist or paired. Keep it that way. Never set GATEWAY_ALLOW_ALL_USERS=true. Chat platforms need no inbound port on the VM.

Step 7: Snapshot the working agent

Once the agent answers you, shut down the VM and take a second snapshot, such as hermes-working. You now have two return points: a clean OS and a known-good agent.

Snapshots, backups and recovery

Snapshots and backups do different jobs. Use both.

ToolWhat it savesUse it when
VM snapshotThe whole VM: OS, agent code and dataBefore every update or big config change
hermes backupA zip of your Hermes data, including credentialsTo move the agent to a new VM, or keep a copy off the VM
hermes update --backupA full backup, then the updateEvery routine update

A safe update routine looks like this:

  1. Take a VM snapshot.
  2. Run hermes update --backup.
  3. Test the agent with one simple task.
  4. If it fails, revert to the snapshot. If it works, delete old snapshots after a few days.

To restore on a fresh VM, install Hermes, then run hermes import with the backup zip. The backup holds your API keys, so store it like a password.

Do not delete ~/.hermes/ to fix a broken install. The docs warn against it, because that folder holds all of your agent's state. Revert the snapshot instead.

Do not keep the data on a shared folder

Hermes stores state in an SQLite database in WAL mode. The Docker docs warn that bind mounts across a VM boundary (virtiofs, 9p and drvfs) can silently corrupt it. Keep ~/.hermes/ on the VM's own disk. Do not move it to a hypervisor shared folder to "save space".

Security hardening checklist

  • Run as a normal user. Never run the gateway as root.
  • Keep approvals on. Leave dangerous-command approval in smart or manual mode. Unattended and cron sessions deny by default.
  • Keep ports closed. The API server (port 8642) is off by default. The dashboard (port 9119) runs only when you start it with hermes dashboard --no-open, and it binds to 127.0.0.1. Reach it through an SSH tunnel: ssh -L 9119:localhost:9119 you@vm-address.
  • Use allowlists for every chat platform.
  • Give the VM no secrets it does not need. Do not copy your SSH keys or cloud credentials into it.
  • Consider a Docker terminal backend. Install Docker Engine in the VM, then set terminal.backend: docker. Shell and file tools then run in a container inside the VM. Note that Hermes skips command approval on this backend, because it treats the container as the boundary.

See the Hermes security guide for the full list.

Alternative: Hermes Agent in Docker inside the VM

If you prefer containers, the official image is nousresearch/hermes-agent, for amd64 and arm64. Install Docker in the VM from the Docker Engine docs for Ubuntu. Use this instead of the native install, not alongside it. Both use ~/.hermes, and two gateways must never share one data folder. Then run the first-time setup:

mkdir -p ~/.hermes
docker run -it --rm \
  -e HERMES_UID=$(id -u) -e HERMES_GID=$(id -g) \
  -v ~/.hermes:/opt/data \
  nousresearch/hermes-agent setup

Then start the gateway:

docker run -d \
  --name hermes \
  --restart unless-stopped \
  -e HERMES_UID=$(id -u) -e HERMES_GID=$(id -g) \
  -v ~/.hermes:/opt/data \
  nousresearch/hermes-agent gateway run

Two differences matter. First, hermes update refuses to run in Docker. You update by pulling a new image. Second, the dashboard runs only if you set HERMES_DASHBOARD=1, and inside the container it binds to 0.0.0.0. If you need it, publish it as -p 127.0.0.1:9119:9119 and use an SSH tunnel. If you use browser tools in Docker, add --shm-size=1g.

Troubleshooting

ProblemFix
hermes: command not foundRun source ~/.bashrc, or check that ~/.local/bin is in your PATH.
Installer exits with no message on minimal UbuntuRun sudo apt install libatomic1, then run the script again.
Installer hangs while it downloads a browserRun bash install.sh --skip-browser, or curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser. Add browser tools later, as the install docs describe.
"API key not set"Run hermes model and enter the key again.
Local Ollama model rejectedRaise the model's context to 64,000 tokens or more.
Config errors after an updateRun hermes config check, then hermes config migrate.
Anything elseRun hermes doctor. If it still fails, revert to your snapshot.

FAQ

Is Hermes Agent free?

The agent is open source under the MIT license. You pay for the model you connect, unless you run a local model. Check your provider's pricing page for current rates.

Can I install Hermes Agent with pip?

No. As of October 2026, the platform page lists pip and PyPI installs as unsupported. Use the official install script or the Docker image.

How much RAM does Hermes Agent need?

The official container figure is 1 GB minimum and 2 to 4 GB recommended. Browser tools need at least 2 GB. For a full Ubuntu VM, 4 GB is a comfortable start.

Does Hermes Agent work on Ubuntu 22.04?

It may work, because the docs say most glibc and systemd distributions are likely to work. As of October 2026, I found no official test of 22.04. Use 24.04 to stay on the tested path.

Is a VM safer than running Hermes on my laptop?

Yes. The agent runs commands on whatever machine it lives on. A VM limits that to a disposable system you can snapshot and revert. It is not perfect isolation, so still keep secrets out of the VM.

Can I run Hermes Agent in a VM on an Apple Silicon Mac?

As of October 2026, Hermes lists Linux on aarch64 as supported, so an ARM Ubuntu VM is a valid target. VMware Fusion Pro can run ARM Ubuntu. Hermes also runs natively on macOS, but then it has access to your Mac.

Related guides

VMware vs VirtualBox vs Proxmox for a Desktop Lab

Illustration of a laptop running three desktop virtualization apps, each hosting a virtual machine

For VMware vs VirtualBox on a desktop lab, both are good, free type 2 apps. VMware Workstation (Windows, Linux) and Fusion (Mac) are polished and, as of October 2026, free for personal and commercial use (verify on Broadcom's site). VirtualBox is open source and runs on all three platforms. Proxmox is a server platform, not a desktop app, but you can run it inside either one to learn it.

Who this is for: you want to run virtual machines on the computer you already own, and you need to pick one tool to start.

What a desktop lab is

A desktop lab is a set of virtual machines on your everyday laptop or desktop. You install a hypervisor app, create VMs, and break things without risk to your main system. It is the cheapest way to start a home lab, because you need no extra hardware.

VMware Workstation, VMware Fusion and VirtualBox are type 2 hypervisors. They run as apps on top of your normal OS. Proxmox VE is a type 1 hypervisor. It installs on bare metal and becomes the OS. If those terms are new, read type 1 vs type 2 hypervisors explained first. The difference shapes everything below.

VMware Workstation and Fusion

VMware makes two desktop products. Workstation Pro runs on Windows and Linux hosts. Fusion Pro runs on macOS. Broadcom now owns VMware.

License

In May 2024, Broadcom dropped the price of Workstation Pro and Fusion Pro to zero for home users. On 11 November 2024, it made them free for all use: personal, commercial and educational. You need no license key. Broadcom sells no support for these free versions. As of October 2026, verify the current license, download steps and any commercial-use rules on Broadcom's site. Start from the Broadcom TechDocs portal and search for Workstation or Fusion. Do not rely on an old blog post (this one included) for license terms.

Strengths

  • Mature, stable and well documented.
  • Good graphics support for desktop guests.
  • Snapshots, clones and virtual networks that are easy to set up.
  • A familiar path if you work with VMware at your job.

Limits

  • Closed source. You depend on Broadcom's choices about pricing and downloads.
  • The download process needs an account on Broadcom's portal. Some users find it confusing.
  • Fusion on Apple Silicon Macs runs ARM guests. You need ARM builds of Windows or Linux, not the usual x86 ISOs. Check the current docs for what is supported.

Oracle VirtualBox

VirtualBox is Oracle's free hypervisor app. It runs on Windows, macOS and Linux hosts. The base package is open source under the GPL.

License

The core VirtualBox package is free for any use. The Extension Pack is different. It adds features such as some USB and remote display support, and it has its own license (the PUEL). That license has limits on use in organizations. As of October 2026, read the license terms on the VirtualBox downloads page before you install the Extension Pack at work.

Strengths

  • Free and open source for the core package.
  • One tool on all three desktop platforms.
  • Large community and many guides.
  • Works well with Vagrant and other automation tools.

Limits

  • Graphics and desktop feel can be less smooth than VMware for some guests.
  • On Windows, VirtualBox can clash with Hyper-V features (WSL2, Windows Sandbox, some security settings). It can run on top of the Windows hypervisor, but performance may drop. Check the VirtualBox manual for the current guidance.
  • Apple Silicon host support is newer than the x86 version. Check the current docs for which guests work.

Proxmox VE: not a desktop tool, but worth learning

Proxmox VE is a server platform. It is based on Debian Linux, uses KVM for VMs and LXC for containers, and you manage it from a web browser. You do not install it as an app on Windows or macOS. You install it on its own machine. The guide to what Proxmox VE is covers the details.

So why is it in this comparison? Because many people start with a desktop app, then move to Proxmox on a spare PC or mini PC. You can try Proxmox first inside VMware or VirtualBox. This is called nested virtualization. A VM runs Proxmox, and Proxmox runs its own VMs inside it.

How to run Proxmox nested

  1. Check that your CPU supports hardware virtualization (Intel VT-x or AMD-V). Turn it on in the BIOS or UEFI.
  2. Download the Proxmox VE ISO from the official site.
  3. Create a VM in VMware or VirtualBox with at least two CPU cores and enough memory for Proxmox plus one small guest.
  4. Turn on nested virtualization in the VM settings. VMware calls it "Virtualize Intel VT-x/EPT or AMD-V/RVI". VirtualBox calls it "Enable Nested VT-x/AMD-V".
  5. Boot the ISO and install Proxmox. Then open its web interface from your host browser.

Menu names change between versions. If a setting is missing, check the docs for your version. Nested guests run slower than guests on bare metal. Use nesting to learn, not to host services you rely on.

Apple Silicon Macs are different. Proxmox VE is built for x86 (Intel and AMD) processors. An M-series Mac uses an ARM processor, so it cannot run Proxmox with hardware virtualization. You can only run it under full x86 emulation, which is very slow. On an Apple Silicon Mac, learn Proxmox on a spare x86 PC or a rented server instead.

For install steps, system requirements and the current release, use the Proxmox VE documentation. As of October 2026, Proxmox VE is free and open source, with an optional paid subscription for the enterprise repository. Verify the current terms on the Proxmox site.

VMware vs VirtualBox vs Proxmox: comparison table

This table reflects the products as of October 2026. Verify every row on the vendor page before you decide. License terms in particular change often.

FactorVMware Workstation / FusionVirtualBoxProxmox VE
Hypervisor typeType 2 (app on your OS)Type 2 (app on your OS)Type 1 (bare metal)
Windows hostYes (Workstation)YesNo (runs nested only)
macOS hostYes (Fusion)Yes (check Apple Silicon support)Intel Macs: nested only. Apple Silicon: emulation only, very slow
Linux hostYes (Workstation)YesIt is the host OS
SourceClosedOpen (core), Extension Pack separateOpen source
CostFree for all use, no paid support (verify)Free core (verify Extension Pack terms)Free, optional paid subscription (verify)
ContainersNoNoYes (LXC)
Web managementNoNoYes
Best forPolished desktop VMs, VMware skillsFree cross-platform labA dedicated home server

What your computer needs

All three tools need a 64-bit CPU with hardware virtualization turned on. Most desktop and laptop CPUs from the last decade have it. Check your BIOS or UEFI if VMs refuse to start.

Memory is the real limit. Your host OS needs its share, and each VM needs its own. Plan for your host plus every VM you want to run at the same time. A fast SSD also helps, since several VMs reading from one slow disk feel sluggish. I do not quote exact numbers here, because they depend on the guests you run. Check each guest OS for its own minimum.

Which one should you pick?

Start from the computer you have and the goal you want.

  • You are on Windows or Linux and want the smoothest desktop VMs. Try VMware Workstation Pro, after you confirm the current license.
  • You want free, open source and the same tool everywhere. Pick VirtualBox.
  • You are on an Apple Silicon Mac. Fusion is the more mature choice for ARM guests today. Check VirtualBox's current Mac support before you rule it out.
  • You use Windows Pro and already need Hyper-V. Consider Microsoft Hyper-V itself. It avoids the clash with other hypervisors.
  • You want a server that runs 24/7. Skip the desktop apps. Put Proxmox on a spare PC. The guide to home server setup walks through the hardware.

My view: install one desktop app, then nest Proxmox inside it for a weekend. If you like Proxmox, move it to real hardware. If you work in a VMware shop, the Proxmox vs VMware comparison covers the server side.

What to watch for

  • Two hypervisors on one host. Running VMware and VirtualBox at the same time can fail or run slowly. Close one before you start the other.
  • Hyper-V features on Windows. WSL2, Docker Desktop and Core Isolation can turn on the Windows hypervisor. Your desktop app then runs on top of it, often slower.
  • Too little memory. Every VM takes RAM from your host. Leave enough for your own OS, or the whole machine slows down.
  • Laptop sleep. Close or suspend VMs before your laptop sleeps. A VM caught mid-write can corrupt its disk.
  • Old license advice. VMware and VirtualBox license terms have changed. Always read the vendor page, not a forum post.

FAQ

Is VMware Workstation free?

Yes, for personal and commercial use since November 2024. Verify on Broadcom's site. As of October 2026, Workstation Pro and Fusion Pro need no license key, and Broadcom sells no support for them. Terms have changed before and may change again.

Is VirtualBox better than VMware?

Neither is better for everyone. VirtualBox is open source and runs on all three desktop platforms. VMware is often smoother for desktop guests and matches skills used at work.

Can I run Proxmox in VirtualBox?

Yes, on an x86 host (Intel or AMD). Turn on nested VT-x/AMD-V in the VM settings and install Proxmox from its ISO. Guests inside the nested Proxmox run slower, so use it for learning only. On an Apple Silicon Mac, Proxmox runs only under x86 emulation, which is too slow for real use.

Can VMware and VirtualBox run on the same computer?

You can install both. Running VMs in both at the same time may fail or run slowly. Close one app before you start VMs in the other.

Is the VirtualBox Extension Pack free?

It is free for personal and educational use, under a different license (the PUEL) from the core package. Commercial use needs a paid license. Since version 7.1, there is no free 30-day evaluation for business use. As of October 2026, read the current terms on the VirtualBox site.

What is the best desktop virtualization software for a beginner?

VirtualBox is a safe first step, since it is free and runs everywhere. VMware Workstation or Fusion is a good choice if you want more polish. On an x86 PC, either one can host a nested Proxmox when you are ready.

Related guides

Containers vs Virtual Machines: When to Use Which

Illustration comparing virtual machines, each with its own operating system layer, to containers sharing one kernel

The core difference in container vs virtual machine is the kernel. A virtual machine (VM) runs a full operating system on virtual hardware, with its own kernel. A container shares the host's kernel and isolates only the processes, files and network. Use a VM when you need strong isolation or a different OS. Use a container when you want to run many Linux services with little overhead.

Who this is for: you run a home lab or a small-team server, and you want to know where each workload should live.

What a virtual machine is

A virtual machine is a complete computer made of software. A hypervisor gives it virtual CPUs, memory, disks and network cards. The VM boots its own operating system, with its own kernel, from its own virtual disk. The guest OS does not know (or care) that the hardware is not real.

The hypervisor is the layer that makes this work. If you want the full picture, read how a hypervisor shares one machine between VMs. For this post, you only need one fact. Each VM carries a full OS, so each VM costs you memory, disk and boot time.

That cost buys you three things:

  • Any OS. A Linux host can run Windows, BSD or a different Linux kernel in a VM.
  • Strong isolation. A crash or a kernel exploit inside the VM stays inside the VM, in most cases.
  • Full control. You can load kernel modules, pass through a GPU or a disk controller, and snapshot the whole machine.

What a container is

A container is a group of processes that the host kernel isolates from everything else. The kernel gives the container its own view of the file system, the process list, the network and the users. Linux does this with namespaces and control groups (cgroups). There is no second kernel and no virtual hardware.

Because there is no guest OS to boot, a container starts fast and uses little memory. You can run many more containers than VMs on the same machine. The limit is simple: a container must use the host's kernel. A Linux host runs Linux containers. It cannot run a Windows container natively.

Containers are one form of OS-level virtualization. The guide to types of virtualization shows where they sit next to server, desktop, storage and network virtualization.

Two kinds of container

Not all containers do the same job. Home lab users meet two kinds:

  • System containers (LXC). An LXC container looks like a small Linux machine. It runs an init system, several services and a shell you log in to. You manage it like a lightweight VM.
  • Application containers (Docker, Podman). A Docker container usually runs one application from an image. You do not log in and patch it. You replace it with a new image when an update comes out.

This split matters when you compare LXC vs Docker. They use the same kernel features, but they suit different habits. See the LXC documentation and the Docker documentation for the details of each.

Container vs virtual machine: side by side

This table sums up the trade-offs. The words "faster" and "lighter" are relative. Real numbers depend on your hardware and workload, so measure your own.

FactorVirtual machineSystem container (LXC)Application container (Docker)
KernelIts ownShared with hostShared with host
Guest OS choiceAny OS the hypervisor supportsLinux only (on a Linux host)Linux images on a Linux host
IsolationStrong (hardware-level)Good, weaker than a VMGood, weaker than a VM
Start timeSlower (full boot)FastFast
Memory overheadHigher (full OS)LowLow
How you update itPatch the OS insidePatch the OS insidePull a new image, recreate
Hardware passthroughYes (GPU, disks, USB, PCIe)Limited, needs host configLimited, needs host config
Best forWindows, appliances, untrusted codeSmall Linux services you manage by handPackaged apps with ready-made images

When a virtual machine wins

Pick a VM when one of these is true:

  • You need a different OS. Windows, pfSense, OPNsense, TrueNAS and many appliances need their own kernel.
  • You run code you do not trust. A test box for downloads or a public-facing service gets more protection in a VM.
  • You need hardware passthrough. A GPU for a media server or a disk controller for a storage VM is simpler in a VM.
  • You need a custom kernel. Some VPN and storage tools need kernel modules the host does not load.
  • You want clean snapshots of a whole system. A VM snapshot covers the OS, the apps and the data disk together.

When a container wins

Pick a container when these are true:

  • The app runs on Linux. Most self-hosted apps do.
  • You want to run many small services. DNS, a reverse proxy, a dashboard and a password manager do not each need a full OS.
  • You have limited memory. A mini PC or an old laptop goes much further with containers.
  • The app ships as a Docker image. If the project publishes an image and a compose file, use them. You get updates the way the developers test them.

In my view, most home labs end up with a mix. A few VMs carry the heavy or sensitive jobs. Many containers carry the small services.

How Proxmox runs both

Proxmox VE is a good place to learn this, because it runs both models from one web interface. It uses KVM for virtual machines and LXC for system containers. If you are new to it, start with what Proxmox VE is and why home labs run it.

In Proxmox, you create a VM or a container from the same menu. Both get an ID, storage, a network bridge and backup jobs. The difference is under the hood. A VM gets virtual hardware. A container shares the Proxmox host kernel.

Proxmox vs Docker: the wrong question

People often search "Proxmox vs Docker". The two are not rivals. Proxmox is a platform that hosts VMs and LXC containers. Docker is a tool that runs application containers inside a Linux system. You can run Docker on Proxmox. The real question is where Docker should live.

Where to run Docker on Proxmox

You have four choices:

  1. Docker inside a VM. Create a Linux VM and install Docker in it. This is the safest option. As of October 2026, the Proxmox documentation says a VM remains a recommended practice for isolation and live migration. Verify this in the Proxmox VE documentation before you decide.
  2. Docker inside an LXC container. This uses less memory. It also needs extra settings (such as nesting), and updates to the host or Docker can break it. Many people run it this way. Treat it as a choice you test, not a default.
  3. Docker on the Proxmox host itself. Do not do this. It mixes your app layer with your hypervisor. A bad update or a firewall rule can take down every guest.
  4. OCI images as app containers. As of October 2026, Proxmox can pull an OCI image (the format Docker uses) and run it as an application container, converted to LXC. This is a technology preview, not for production. Check the Proxmox docs for its current status.

A simple pattern works for most labs. Run one Linux VM for all your Docker apps. Run LXC containers for small standalone services. Run separate VMs for Windows, firewalls and anything that needs passthrough.

Common mistakes

  • Thinking a container is as isolated as a VM. It is not. All containers share one kernel. A kernel flaw can affect every container on the host. Keep risky workloads in VMs.
  • Running containers as root without need. Use unprivileged LXC containers where you can. For Docker, read the security section of the Docker docs.
  • Putting one app per VM by habit. Ten VMs for ten small apps wastes memory. Group small Linux apps in containers.
  • Storing data inside the container. When you recreate a Docker container, data inside it goes away. Use volumes or bind mounts, and back them up.
  • Skipping backups because containers are "disposable". The container is disposable. Your data and your config are not.
  • Forgetting the host is a single point of failure. VMs and containers on one box all stop when the box stops. The post on disadvantages of server virtualization covers how to plan for this.

A quick way to decide

Ask these questions in order. Stop at the first "yes".

  1. Does it need a non-Linux OS or its own kernel? Use a VM.
  2. Does it need GPU or disk passthrough? Use a VM.
  3. Is it untrusted, or exposed to the internet with no proxy in front? Use a VM.
  4. Does the project ship an official Docker image? Run it in Docker, inside a VM.
  5. Is it a small Linux service you want to manage like a server? Use an LXC container.

This is a starting rule, not a law. Change it when your own tests show a better fit.

FAQ

Is a container faster than a virtual machine?

A container usually starts faster and uses less memory, because it does not boot a second OS. For CPU-heavy work, the gap is often small, since modern VMs use hardware virtualization. Measure your own workload before you decide on speed alone.

Is a container more secure than a VM?

No. A VM has stronger isolation, because each VM has its own kernel. Containers share the host kernel, so one kernel flaw can reach all of them. Containers can still be safe when you keep them unprivileged and patched.

What is the difference between LXC and Docker?

Both use the same Linux kernel features. LXC runs a full Linux userland that you manage like a small server. Docker runs one packaged application from an image, and you replace the container to update it.

Can I run Docker inside a virtual machine?

Yes, and it is a common setup. You install a Linux VM, then install Docker in it. On Proxmox this keeps Docker away from the host and makes backups simple.

Can a container run Windows on a Linux host?

No. A container shares the host kernel, so a Linux host runs Linux containers. To run Windows on a Linux host, use a VM.

Do I need Proxmox to use containers?

No. You can run Docker or LXC on any Linux system. Proxmox adds a web interface, backups and VMs in one place, which helps when your lab grows.

Related guides