advanced kvm (libvirt / virsh) configuration for datacenter

Job ID: 30951682

Budget: €750 – €1,500 EUR

Hi I'm looking for the following features for a kvm + libvirt architecture:

the vm must automatically take its ip (and network configuration) from dhcp or cloud-init, whatever you suggest it's better from your experience

the vm can't sniff unwanted traffic if the 'owner' manually changes its ip (or network configuration)

the vms must have a private network (vpc = Virtual Private Cloud network)
which is encrypted
and can't be tapped from other unauthorized vms

the vpc should be usable also from other vms of other hosts
(vm 'A' on host 'A' should be able to use the same vpc with vm 'B' on host 'B')

the internet network bandwidth of each vm must be limited to 100mb/s
but burst up to 1gb/s
(coherently with the other vms of the host, meaning they can't 'starve' each other)

the vpc network bandwidth of each vm must be limited to 1gb/s
(but if possible, the sum of the vpc consumption from all the vms on the host can't exceed 15gb/s)

the network bandwidth usage of the vms should be logged, so that i can build reports and graphs with history

the cpu usage of the vms should be logged, so that i can build reports and graphs with history

the ram/memory usage of the vms should be logged, so that i can build reports and graphs with history

the vms must have each their own vnc session
always on the same port (or X port i guess)
and compatibile with a web based vnc client

check and eventually tweak the configuration
to have comparable performance as the host

check the cpu siblings/affinity/capabilities configuration if it's correct

the host will use debian 10
(and soon debian 11)
and some libvirt commands must be usable from users other than root
(for example www-data, using polkit i guess)

please bid only if you are an expert in this field
and have previous, production quality experience

(long term relationship will be considered for europe-area based consultants)


Thank you