GUEST(7)Miscellaneous Information ManualGUEST(7)

guest — the OpenBSD system in each VM

OpenBSD -current (now 8.0-current), amd64; see https://www.openbsd.org/faq/current.html. One user, , in group wheel, with doas(1) without password; root cannot log in over ssh. Your account keys are installed at boot. Each VM generates its own ssh host key on first boot.

The kernel is supplied by the host: -current with patches for Firecracker, which are not in the OpenBSD tree. -current has no errata and no syspatch(8): security fixes come with a rebuild of the image on a newer -current, which can lag the fix in the tree. Kernel and userland come from the image: new VMs start from the latest one, existing VMs keep theirs until upgrade(1). The patches are not published yet; whether to publish them is decided after the beta.

Outbound IPv4 leaves from one address shared by all VMs.

Each VM has its own public IPv6 address, shown by stat, open to the internet on every port: filter it with pf.conf(5) in the VM. The address is drawn at random and stays with the VM for its whole life, across restart, upgrade and rename; a copy or a restored backup gets its own. After rm it is retired and never given to another VM.

Outbound ports 25, 465 and 587 are blocked over IPv4 and IPv6; 2525 is open, and many mail relays accept it.

doas(1), new(1), stat(1), upgrade(1), pf.conf(5), beta(7), website(7)

chroot.devOctober 10, 2026GUEST(7)