---
title: Accessing a virtual machine  by using its internal FQDN
---

# Accessing a virtual machine  by using its internal FQDN {#virt-accessing-vm-internal-fqdn}

You can access a virtual machine on a stable, fully qualified domain name (FQDN) by using headless services. A headless service creates DNS records for each pod instead of a virtual IP, enabling FQDN access without exposing specific ports.

> [!IMPORTANT]
> If you created a VM by using the OpenShift Container Platform web console, you can find its internal FQDN listed in the **Network** tile on the **Overview** tab of the **VirtualMachine details** page.

## Creating a headless service in a project by using the CLI {#virt-creating-headless-services_virt-accessing-vm-internal-fqdn}

To create a headless service in a namespace, add the `clusterIP: None` parameter to the service YAML definition.

**Prerequisites**

- You have installed the OpenShift CLI (`oc`).

**Procedure**

1. Create a `Service` manifest to expose the VM, such as the following example:

   ```yaml
   apiVersion: v1
   kind: Service
   metadata:
     name: mysubdomain
   spec:
     selector:
       expose: me
     clusterIP: None
     ports:
     - protocol: TCP
       port: 1234
       targetPort: 1234
   ```

   - `metadata.name` defines the name of the service. This must match the `spec.subdomain` attribute in the `VirtualMachine` manifest file.
   - `spec.selector` defines the service selector that must match the `expose:me` label in the `VirtualMachine` manifest file.
   - `spec.clusterIP` defines a headless service.
   - `spec.ports` defines the list of ports that are exposed by the service. You must define at least one port. This can be any arbitrary value as it does not affect the headless service.
2. Save the `Service` manifest file.
3. Create the service by running the following command:

   ```terminal
   $ oc create -f headless_service.yaml
   ```

## Mapping a virtual machine to a headless service by using the CLI {#virt-discovering-vm-internal-fqdn_virt-accessing-vm-internal-fqdn}

To connect to a virtual machine (VM) from within the cluster by using its internal fully qualified domain name (FQDN), you must first map the VM to a headless service. Set the `spec.hostname` and `spec.subdomain` parameters in the VM configuration file.

If a headless service exists with a name that matches the subdomain, a unique DNS A record is created for the VM in the form of `<vm.spec.hostname>.<vm.spec.subdomain>.<vm.metadata.namespace>.svc.cluster.local`.

**Prerequisites**

- You have installed the OpenShift CLI (`oc`).

**Procedure**

1. Edit the `VirtualMachine` manifest to add the service selector label and subdomain by running the following command:

   ```terminal
   $ oc edit vm <vm_name>
   ```

   Example `VirtualMachine` manifest file:

   ```yaml
   apiVersion: kubevirt.io/v1
   kind: VirtualMachine
   metadata:
     name: vm-fedora
   spec:
     template:
       metadata:
         labels:
           expose: me
       spec:
         hostname: "myvm"
         subdomain: "mysubdomain"
   # ...
   ```

   - `spec.template.metadata.labels.expose` defines a label that must match the `spec.selector` attribute of the `Service` manifest that you previously created.
   - `spec.template.spec.hostname` defines the hostname. If this attribute is not specified, the resulting DNS A record takes the form of `<vm.metadata.name>.<vm.spec.subdomain>.<vm.metadata.namespace>.svc.cluster.local`.
   - `spec.template.spec.subdomain` defines the subdomain. The `spec.subdomain` attribute must match the `metadata.name` value of the `Service` object.
2. Save your changes and exit the editor.
3. Restart the VM to apply the changes.

## Connecting to a virtual machine by using its internal FQDN {#virt-connecting-vm-internal-fqdn_virt-accessing-vm-internal-fqdn}

You can connect to a virtual machine (VM) by using its internal fully qualified domain name (FQDN).

**Prerequisites**

- You have installed the `virtctl` tool.
- You have identified the internal FQDN of the VM from the web console or by mapping the VM to a headless service. The internal FQDN has the format `<vm.spec.hostname>.<vm.spec.subdomain>.<vm.metadata.namespace>.svc.cluster.local`.

**Procedure**

1. Connect to the VM console by entering the following command:

   ```terminal
   $ virtctl console vm-fedora
   ```
2. To connect to the VM by using the requested FQDN, run the following command:

   ```terminal
   $ ping myvm.mysubdomain.<namespace>.svc.cluster.local
   ```

   Example output:

   ```terminal
   PING myvm.mysubdomain.default.svc.cluster.local (10.244.0.57) 56(84) bytes of data.
   64 bytes from myvm.mysubdomain.default.svc.cluster.local (10.244.0.57): icmp_seq=1 ttl=64 time=0.029 ms
   ```

   In the preceding example, the DNS entry for `myvm.mysubdomain.default.svc.cluster.local` points to `10.244.0.57`, which is the cluster IP address that is currently assigned to the VM.

**Additional resources**
{._additional-resources}

- [Exposing a VM by using a service](/openshift-docs-markdown/virt/vm_networking/virt-exposing-vm-with-service#virt-exposing-vm-with-service)
