# Core Concepts

This page summarizes the five design ideas behind QemuRun-pve; each topic page has the full details.

## The VMID Is the Last IP Octet

Each VM's IP is the first three octets of `GATEWAY` plus its VMID, e.g. VMID `120` → `192.168.0.120/24`. The service keeps no IP table: knowing the VMID means knowing the IP.

→ [VMID and IP Allocation](/vmid-ip-allocation)

## One Call, Staged Provisioning

`POST /api/vm/install` runs preparation, image download, creation, cloud-init injection, boot, the init script, and a reboot in order, reporting each step's result and duration over SSE.

→ [Provisioning Pipeline](/provisioning-pipeline), [OS Init Scripts](/os-init-scripts)

## Cluster CPU Baseline

New VMs get the lowest x86-64 level common to every node, so they can later migrate to any node and still boot.

→ [CPU Baseline](/cpu-baseline)

## Transparent Node Dispatch

The service runs only on the main node; it calls `qm` directly for VMs there and over SSH for VMs elsewhere, so callers never need to know where a VM lives.

→ [Multi-Node Dispatch](/multi-node-dispatch)

## Layered Access Guards

Browser origins are limited by subnet-scoped CORS, mutating calls by `ALLOW_IPS`, and individual VMs by the disabled list and their run state.

→ [Access Control](/access-control)
