Skip to content

docs: audit published build 6ab146c1226c6b08d118e115 - #341

Draft
NikolayVoina wants to merge 2 commits into
cloudlinux:masterfrom
NikolayVoina:docs-audit/build-5f7ca2852b52
Draft

NikolayVoina wants to merge 2 commits into
cloudlinux:masterfrom
NikolayVoina:docs-audit/build-5f7ca2852b52

Conversation

@NikolayVoina

@NikolayVoina NikolayVoina commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Documentation audit: published build 6ab146c1226c6b08d118e115

Outcome: iteration_limit. Channel: Beta.

This audit compares pinned published product sources with the official documentation. A completed source review does not establish installed OS/panel behavior. Beta instructions apply only to Beta until confirmed for Stable.

Applicability

Shared source commit verified for: CL10, CL7, CL8, CL9, ubuntu22_04_ext. Package payloads inspected: CL10. Product versions: lve 2.2.

Proposed documentation changes

The exact documentation patch is below. It preserves the surrounding instructions; review the changed commands and conditions together with their affected section.

  • docs/cloudlinuxos/cloudlinux_installation/README.md

  • docs/cloudlinuxos/command-line_tools/README.md

  • docs/cloudlinuxos/isolates/README.md

  • docs/cloudlinuxos/limits/README.md

Independent review

Pass Assessment

| Factual accuracy | 6.5/10 |

| Integration quality | 6/10 |

Blocking issues: 10. Necessary unsupported claims: 14. Each applicable score must be at least 8; an average never overrides a failed pass. A score covers only the inspected scope.

Technical checks and limits

Technical gate: passed; 233/271 individual checks passed. 38 unchanged failures also occur on the pinned master baseline. The gate requires the existing VuePress build and applicable changed-page checks. OS/panel commands are not executed by this tool; unavailable installed-version evidence remains a gap.

Completed cycles: 2. Reserved cycles: 2. Estimated model cost: $11.4999232. Total input/output tokens including reasoning: 18412301.

Cost is estimated from reported usage; token totals include reasoning.

Remaining review

Review completed but was not accepted within the selected cycle limit. Outstanding corrections and evidence gaps remain in the private report; the draft is not approved.

Private source excerpts, credentials, raw build logs and agent evidence are excluded from this public article. Product engineer and documentation owner approval are required. This PR stays Draft; no automatic merge.

Exact public documentation diff

diff --git a/docs/cloudlinuxos/cloudlinux_installation/README.md b/docs/cloudlinuxos/cloudlinux_installation/README.md
index f9491a6..1feef79 100644
--- a/docs/cloudlinuxos/cloudlinux_installation/README.md
+++ b/docs/cloudlinuxos/cloudlinux_installation/README.md
@@ -386,53 +386,50 @@ Use the logs that the conversion already creates:
 Preserve the failed run's logs before a retry. Review them locally and remove activation keys, passwords, tokens, and private customer information from any copy you share. Do not paste full logs or license keys into a public issue.
 
 #### When to stop and escalate
 
 If the recovery procedure is unclear, the server has conflicting release or core packages, or you cannot confirm a safe boot configuration, stop before further package changes or a reboot. Search the [knowledge base](https://cloudlinux.zendesk.com/hc/en-us) for the exact error. If no matching procedure applies, [contact support](https://cloudlinux.zendesk.com/hc/en-us/requests/new) through the private channel with the existing conversion log, the first failed step, the source OS and panel versions, and the command used with secrets removed. Include any changes made after the failure.
 
 This is an exception path for an unsafe or unknown state. For an eligible server that has not been partially converted, the normal conversion and validation steps above are the self-service path.
 
 #### Server panics or reboots during conversion on Intel CPUs with IBT
 
-When converting **AlmaLinux 10 to CloudLinux 10** on a server that Intel CPU supports **IBT** (Indirect Branch Tracking), the server may panic and reboot during the LVE setup step of `cldeploy`, leaving a half-converted system that may not boot back up.
+During **AlmaLinux 10 to CloudLinux 10** conversion, loading the LVE module while the running kernel enforces **IBT** (Indirect Branch Tracking) can cause a kernel panic and leave the server partially converted. An Intel CPU's IBT flag alone does not mean that the running kernel enforces IBT.
 
 The kernel message (visible on the console, in `/var/log/messages`, or in a kdump vmcore) looks like:
 
 ```text
 Missing ENDBR: put_filesystem+0x0/0x20
 kernel BUG at arch/x86/kernel/cet.c:102!
  ... mount_cgroup_root_fs+0x209/0x260 [kmodlve]
 ```
 
-**Cause.** The CloudLinux LVE kernel module (`kmod-lve`) requires Intel CET/IBT to be disabled.
-The CloudLinux `tuned` profile turns it off via the `ibt=off` kernel boot parameter, but that takes effect only after a reboot.
-If the module is loaded while IBT is still active - before that reboot - the CPU raises a control-protection fault and the
-kernel panics.
+**Cause.** The LVE kernel module (`kmodlve`) cannot be loaded safely while the running kernel enforces Intel IBT. The `ibt=off` kernel boot parameter takes effect only after a reboot; loading the module before that can raise a control-protection fault and panic the kernel.
 
-**Recovery for an affected server.** Boot once with IBT disabled:
+**Recovery for an affected server.** Add `ibt=off` at the GRUB menu for a single boot:
 
 1. At the GRUB boot menu, highlight the default entry and press `e` to edit it.
 2. Find the line that starts with `linux` (the kernel command line) and append ` ibt=off` to its end.
 3. Press `Ctrl+X` (or `F10`) to boot with that parameter.
 
-Once the server is back up, verify that the conversion left the CloudLinux `tuned` profile active - it sets `ibt=off` permanently, so the parameter is applied automatically on every subsequent boot:
+The GRUB edit above affects one boot only. After a normal reboot, check the active `tuned` profile and whether `ibt=off` is present as a separate argument on the running kernel's command line:
 
 ```bash
-tuned-adm active                 # expect a "cloudlinux-*" profile
-grep -o 'ibt=off' /proc/cmdline  # after a normal reboot, expect: ibt=off
+tuned-adm active                 # check for a "cloudlinux-*" profile
+grep -qE '(^| )ibt=off( |$)' /proc/cmdline && echo 'ibt=off is on the kernel command line'
 ```
 
-If the conversion did not finish, or `ibt=off` is not applied on a normal boot, attach
+If the conversion did not finish, or `ibt=off` is absent from the kernel command line after a normal reboot, attach
 `/var/log/cldeploy.log` and contact [CloudLinux support](https://cloudlinux.zendesk.com/hc/en-us).
 
 :::tip Note
-Up-to-date versions of `cldeploy` and the CloudLinux LVE packages avoid this by not loading the LVE module until after the post-conversion reboot, when `ibt=off` is already in effect.
+When the LVE service detects kernel IBT enforcement and `ibt=off` is absent, it reports a deferred module load and exits successfully. A successful `lve.service` start does not by itself mean `kmodlve` is loaded. After reboot, check with `lsmod | grep '^kmodlve '`; if the module is absent, review the LVE service logs and contact support instead of manually loading it while IBT is enforced.
 :::
 
 ### How to enable Secure Boot for CloudLinux 9+
 
 #### Overview
 CloudLinux 9 and above use a non-modified AlmaLinux kernel.
 To make Secure Boot work with CloudLinux's kernel module, you need to enroll the CloudLinux secure boot key onto your server.
 The following procedure shows how to do it.
 
 #### Requirements
diff --git a/docs/cloudlinuxos/command-line_tools/README.md b/docs/cloudlinuxos/command-line_tools/README.md
index 5750117..5fe0d7e 100644
--- a/docs/cloudlinuxos/command-line_tools/README.md
+++ b/docs/cloudlinuxos/command-line_tools/README.md
@@ -2897,33 +2897,33 @@ cldeploy --hostinglimits                            # update httpd and install m
 | <span class="notranslate"> `reload-binaries` </span> |re-load list of binaries from config file|
 | <span class="notranslate"> `help (-h)` </span> |show this message|
 | <span class="notranslate"> `version (-v)` </span> |version number|
 | <span class="notranslate"> `lve-version` </span> |LVE version number|
 | <span class="notranslate"> `set-reseller` </span> |create LVE container and set LVE parameters for a reseller|
 | <span class="notranslate"> `set-reseller-default` </span> |set default limits for resellers users|
 | <span class="notranslate"> `remove-reseller`</span> |delete LVE container and the record in the config, move LVE containers to the host container|
 
 **Per-domain commands**
 
-These manage [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain) — resource limits for an individual website rather than for the whole account. They require a kernel with per-domain LVE support; on a kernel without it every one of them exits with code `38` and the message <span class="notranslate">`Domain limits are not supported by this kernel`</span>.
+These manage [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain) — resource limits for an individual website rather than for the whole account. They require a compatible LVE library and running kernel. On an initialized LVE system without the per-domain interface, <span class="notranslate">`list-domains`</span>, <span class="notranslate">`allow-domain-limits`</span>, <span class="notranslate">`deny-domain-limits`</span>, <span class="notranslate">`enable-domain-limits`</span> and <span class="notranslate">`disable-domain-limits`</span> exit with code `38` and report <span class="notranslate">`Domain limits are not supported by this kernel (requires lve_lvp_create2)`</span>. <span class="notranslate">`regenerate-domains`</span> can return without updating anything when that interface is unavailable; its exit status does not verify that a domain LVE exists.
 
 |  |  |
 |--|--|
 | <span class="notranslate"> `list-domains <uid>` </span> |list the domain LVEs inside the user LVP of the account with the given numeric <span class="notranslate">UID</span>. Reports <span class="notranslate">`UID ... does not exist`</span> for an unknown account and <span class="notranslate">`No domain limits configured for UID ...`</span> for a known one that has none|
 | <span class="notranslate"> `allow-domain-limits <user>` </span> |create the user LVP and allow per-domain limits for the named user (idempotent)|
 | <span class="notranslate"> `deny-domain-limits <user>` </span> |remove the user LVP and disallow per-domain limits for the named user|
 | <span class="notranslate"> `enable-domain-limits <domain>` </span> |register a domain LVE under its owner's LVP. The owner and document root are resolved from the control panel, so only the domain name is given|
 | <span class="notranslate"> `disable-domain-limits <domain>` </span> |unregister the domain LVE and remove its registry entry|
 | <span class="notranslate"> `regenerate-domains --username <user> [--domain <name>] [--old-domain <name>] [--old-docroot <path>]` </span> |update the domain configuration and id mapping after a domain rename, a document root change, or a user rename. <span class="notranslate">`--username`</span> is required|
 
 :::tip Note
-Under a control panel you normally do not call these directly — <span class="notranslate">`cagefsctl --site-isolation-allow`</span>, <span class="notranslate">`--site-isolation-deny`</span>, <span class="notranslate">`--site-isolation-enable`</span> and <span class="notranslate">`--site-isolation-disable`</span> invoke the matching <span class="notranslate">`lvectl`</span> command for you, and the panel hooks call <span class="notranslate">`regenerate-domains`</span> on rename and document-root changes. Use <span class="notranslate">`lvectl`</span> directly for integration scripts and for inspecting or repairing state. See [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain).
+Under a supported control panel you normally do not call these directly — <span class="notranslate">`cagefsctl --site-isolation-allow`</span>, <span class="notranslate">`--site-isolation-deny`</span>, <span class="notranslate">`--site-isolation-enable`</span> and <span class="notranslate">`--site-isolation-disable`</span> manage filesystem isolation and conditionally call the matching <span class="notranslate">`lvectl`</span> command when the panel and running kernel permit it; automatic enablement also requires a statistics backend with per-domain support. Panel hooks call <span class="notranslate">`regenerate-domains`</span> on rename and document-root changes when applicable. Use <span class="notranslate">`lvectl`</span> directly for integration scripts and for inspecting or repairing state where the kernel supports per-domain LVPs; verify the statistics prerequisite before enabling domain limits. See [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain).
 :::
 
 **Options**
 
 |  |  |
 |--|--|
 | <span class="notranslate"> `--enter-count`   </span> |enable limit for enters count (by default disabled), use only with command "limit". Supported in lve-utils-6.1.2-1 or later. |
 | <span class="notranslate"> `--io-and-memory`   </span> |enable limit for IO and memory (by default disabled), use only with command "limit". Supported in lve-utils-6.1.2-1 or later. |
 | <span class="notranslate"> `--cpu=N`   </span> |limit <span class="notranslate">`CPU`</span> usage; (deprecated. Use <span class="notranslate">`--speed`</span>)|
 | <span class="notranslate"> `--speed=N%` </span> |limit <span class="notranslate">`CPU`</span> usage in percentage; 100% is one core|
diff --git a/docs/cloudlinuxos/isolates/README.md b/docs/cloudlinuxos/isolates/README.md
index 5ffae29..17613a0 100644
--- a/docs/cloudlinuxos/isolates/README.md
+++ b/docs/cloudlinuxos/isolates/README.md
@@ -1,13 +1,13 @@
-# CloudLinux Isolates (BETA)
+# CloudLinux Isolates
 
-CloudLinux Isolates isolates the individual websites of a single hosting account from one another. It has two layers, which are described in turn below:
+CloudLinux Isolates can isolate websites within one hosting account when its [CageFS prerequisites](#prerequisites) are met. Per-domain LVE resource limits have [additional prerequisites](#per-domain-prerequisites). The two layers are described in turn below:
 
 * **[CageFS per domain](#cagefs-per-domain)** — *filesystem* isolation, so that a compromised website cannot reach another site's files.
 * **[LVE per domain](#lve-per-domain)** — *resource* isolation, so that one website's CPU, memory and I/O usage is limited and accounted for on its own.
 
 ## CageFS Per Domain
 
 CloudLinux Isolates is a security feature that provides domain-level isolation within CageFS. It allows server administrators to isolate individual websites from each other, even when they belong to the same hosting account. This prevents cross-site attacks where a compromised website could access files or data from other websites on the same account.
 
 ### Overview
 
@@ -870,38 +870,38 @@ CloudLinux Isolates integrates automatically with supported control panels. When
 * **Renamed**: Isolation configuration is automatically updated
 * **Deleted**: Isolation configuration is automatically cleaned up
 * **Document root changed**: Configuration is regenerated via hooks
 
 ***
 
 ## LVE Per Domain
 
 CloudLinux Isolates also allows resource limits — CPU, memory, I/O, processes and entry processes — to be applied to an *individual website* rather than to the hosting account as a whole. A single busy or misbehaving site is then throttled on its own, without consuming the resources its sibling sites on the same account depend on.
 
-:::warning BETA
-Per-domain LVE limits are a BETA feature, supported on CloudLinux OS 8 and 9.
+:::warning
+Per-domain LVE limits have [additional prerequisites](#per-domain-prerequisites) on CloudLinux OS 8 and 9, including a compatible running kernel, an LVE-capable panel and a statistics backend that supports per-domain reporting. Enabling filesystem isolation alone does not establish per-domain resource limits.
 :::
 
 ### How it relates to CageFS per domain
 
 The two halves of CloudLinux Isolates are separate layers and can be reasoned about separately:
 
 | | |
 |-|-|
-|[CageFS per domain](#cagefs-per-domain) | *Filesystem* isolation — a compromised website cannot read another site's files. Always available where CageFS is.|
-|LVE per domain | *Resource* isolation — a website has its own CPU, memory, I/O and process limits. Requires CloudLinux OS 8 or 9 and the package versions listed under [Per-Domain Prerequisites](#per-domain-prerequisites).|
+|[CageFS per domain](#cagefs-per-domain) | *Filesystem* isolation — a compromised website cannot read another site's files when the [CageFS prerequisites](#prerequisites), including a compatible web server, PHP handler and panel, are met.|
+|LVE per domain | *Resource* isolation — a website can have its own CPU, memory, I/O and process limits where the [per-domain prerequisites](#per-domain-prerequisites) are met. These instructions cover CloudLinux OS 8 and 9; confirm the kernel and panel capabilities before relying on this layer.|
 
-In practice you do not enable them separately. The <span class="notranslate">`cagefsctl --site-isolation-*`</span> commands documented above drive both: each one invokes the matching <span class="notranslate">`lvectl`</span> per-domain command for you when the prerequisites are met, and silently skips that step when they are not. So on a server that does not support per-domain LVEs, website isolation still works — you get the filesystem separation without the resource limits, rather than an error.
+The <span class="notranslate">`cagefsctl --site-isolation-*`</span> management commands handle the CageFS layer. On a panel that supports LVE, allow/enable operations also call <span class="notranslate">`lvectl`</span> when the running kernel supports per-domain limits and the statistics backend has the required capability. If these conditions are not met, a successful filesystem-isolation command does not establish that a domain LVE was created. Deny/disable operations attempt LVE cleanup when the panel and kernel permit it; check for remaining domain LVEs rather than assuming cleanup succeeded.
 
 ### Per-Domain Prerequisites
 
-Per-domain LVE limits are supported on CloudLinux OS 8 and 9. CloudLinux OS 7 predates the required kernel interface; on it, commands that need per-domain support fail with exit code `38` and the message <span class="notranslate">`Domain limits are not supported by this kernel`</span>.
+For per-domain LVE limits on CloudLinux OS 8 or 9, a running kernel with per-domain LVP support is required. On CloudLinux OS 7, the CageFS filesystem layer is separate and remains subject to its own [prerequisites](#prerequisites); do not assume per-domain LVE support. On an initialized LVE system lacking the per-domain interface, the <span class="notranslate">`lvectl`</span> commands that require it report <span class="notranslate">`Domain limits are not supported by this kernel (requires lve_lvp_create2)`</span> with exit code `38`; see [lvectl](/cloudlinuxos/command-line_tools/#lvectl).
 
 In addition to the [CloudLinux Isolates prerequisites](#prerequisites), per-domain LVE limits require:
 
 | Package | Minimum Version |
 | ---------- | --------------- |
 | lve-stats3 | 5.1.0-1         |
 | lve-utils  | 6.6.40-1        |
 
 To check the installed versions:
 
@@ -928,37 +928,37 @@ tools report for an account is the total for everything beneath it — its own
 processes *and* every isolated website. The account's own processes are a
 separate container at the same level as the websites, and are never reported on
 their own.
 
 Because the websites are siblings of the account's own container rather than nested inside it, work done by an isolated website is charged to that website and to the account total, but never to the account's own processes — and the reverse holds too, so an account's cron jobs are never absorbed by one of its websites.
 
 **Limits nest, even though usage does not.** A domain is bounded by its account's limits, which are in turn bounded by the reseller's; raising a domain's limit above its account's does not grant it more than the account has. A domain with no explicit limits of its own is simply bounded by its account's — registering a domain does not, by itself, restrict it.
 
 ### Enabling per-domain limits
 
-Under a control panel, use the [`cagefsctl --site-isolation-*` commands](#command-reference) — they enable both isolation layers together and are the supported administrator path.
+Under a supported control panel, use the [`cagefsctl --site-isolation-*` commands](#command-reference) as the administrator path for filesystem isolation. They attempt to manage per-domain LVEs only when the [additional prerequisites](#per-domain-prerequisites) and the panel's LVE capability are present; verify that the domain LVE exists before setting its limits.
 
-The underlying <span class="notranslate">`lvectl`</span> commands are available for integration scripts, and for inspecting or repairing state:
+The underlying <span class="notranslate">`lvectl`</span> commands are available for integration scripts and for inspecting or repairing state when the running kernel supports per-domain LVPs. Before using them to enable domain limits, also check the statistics prerequisite:
 
 | | |
 |-|-|
 |<span class="notranslate">`lvectl allow-domain-limits <user>`</span> | Create the account's LVP and allow per-domain limits for it. Idempotent.|
 |<span class="notranslate">`lvectl deny-domain-limits <user>`</span> | Remove the account's LVP and disallow per-domain limits.|
 |<span class="notranslate">`lvectl enable-domain-limits <domain>`</span> | Register a domain LVE. The owner and document root are resolved from the control panel.|
 |<span class="notranslate">`lvectl disable-domain-limits <domain>`</span> | Unregister the domain LVE and remove its registry entry.|
 |<span class="notranslate">`lvectl list-domains <uid>`</span> | List the domain LVEs of the account with the given numeric UID.|
 |<span class="notranslate">`lvectl regenerate-domains --username <user> ...`</span> | Refresh the domain configuration and id mapping after a rename or document root change.|
 
 See [lvectl](/cloudlinuxos/command-line_tools/#lvectl) for the full syntax.
 
 :::tip Note
-<span class="notranslate">`lvectl list-domains`</span> lists the members of an account's LVP. For a *reseller*, that LVP holds the reseller's member accounts rather than domains, so the command's output alone does not tell you whether an account is isolated. A member account resolves in <span class="notranslate">`/etc/passwd`</span>; a domain LVE id never does.
+<span class="notranslate">`lvectl list-domains`</span> lists the members of an account's LVP. For a *reseller*, that LVP holds the reseller's member accounts rather than domains, so the command's output alone does not tell you whether an account is isolated. Do not use a <span class="notranslate">`/etc/passwd`</span> lookup alone to decide whether a numeric ID represents an account or a domain. If an ID appears to identify both, stop and contact support before changing its limits.
 :::
 
 The domain renaming, document root changes and account renames performed through a supported control panel are handled by the panel hooks, which call <span class="notranslate">`lvectl regenerate-domains`</span> automatically. Run it by hand only after changing these outside the panel.
 
 ### Setting per-domain limits
 
 Per-domain limits are set by the account owner with [`isolatectl limits`](#per-domain-resource-limits), not by the administrator: there is no <span class="notranslate">`lvectl`</span> command that sets an individual domain's limits. Administrators control the account-level limits, which bound every domain underneath them.
 
 Where the state lives:
 
@@ -1000,39 +1000,39 @@ account  =  the account's own work  +  site1.com  +  site2.com  + ...
              an isolated website)
 ```
 </div>
 
 **Faults are counted per container, then rolled up.** The kernel records a fault only against the container whose limit refused the request. <span class="notranslate">lve-stats</span> then rolls a website's faults into its account's total, so an account read *without* a per-domain option already includes its websites' faults; passing <span class="notranslate">`--with-domains`</span> splits them apart again. The [user notification email](/cloudlinuxos/cloudlinux_os_components/#customize-lve-stats2-notifications) is the one place that subtracts them instead, so that the same refusal is not reported twice in a message that already lists the site.
 
 **Per-domain history is kept for fewer days than per-account history** — 7 days against 30, by default. A report covering a longer range returns correspondingly less per-domain data than account data, without the rows themselves indicating why. Both windows are administrator-configurable; see <span class="notranslate">`keep_history_days_domain`</span> in [LVE-Stats 2 configuration](/cloudlinuxos/cloudlinux_os_components/#configuration) (<span class="notranslate">`/etc/sysconfig/lvestats2`</span>).
 
 ### Fault notifications
 
-When a website hits one of its own limits, the notification sent to the account owner names the website that faulted, alongside the limit it hit. Notifications continue to be addressed per account, and the thresholds and period that govern the account-level notification govern the per-domain section too — so enabling per-domain limits does not, by itself, change who is emailed or how often.
+When fault notifications to account owners are enabled and a website hits one of its own limits, the notification names the website that faulted, alongside the limit it hit. Notifications continue to be addressed per account and follow the configured thresholds and period; enabling per-domain limits does not itself enable notifications or change who receives them.
 
 Administrators customising the email templates should see the <span class="notranslate">`domain_faults`</span> variable in [Customize LVE-stats2 notifications](/cloudlinuxos/cloudlinux_os_components/#customize-lve-stats2-notifications).
 
 ### Troubleshooting per-domain limits
 
 **"Domain limits are not supported by this kernel (requires lve_lvp_create2)"**
 
-The kernel predates per-domain LVE support. Per-domain limits require CloudLinux OS 8 or 9; on CloudLinux OS 7 the [CageFS half](#cagefs-per-domain) of CloudLinux Isolates is still available.
+The running LVE library or kernel does not provide the per-domain interface required by these commands. On CloudLinux OS 8 or 9, check the [per-domain prerequisites](#per-domain-prerequisites); on CloudLinux OS 7 the [CageFS half](#cagefs-per-domain) is separate and still requires its own prerequisites.
 
 **Isolation was enabled, but no domain LVEs were created**
 
-The <span class="notranslate">`cagefsctl --site-isolation-*`</span> commands always apply the filesystem layer, and add the per-domain LVE only when the [prerequisites](#per-domain-prerequisites) are met. Check the installed versions:
+<span class="notranslate">`cagefsctl --site-isolation-enable`</span> can configure filesystem isolation without creating a domain LVE. Automatic LVE enablement also requires an LVE-capable panel, a compatible running kernel and [per-domain prerequisites](#per-domain-prerequisites). Check the installed packages:
 
 ```
 rpm -q lve-stats3 lve-utils
 ```
 
-If either is below the minimum, update it and then re-run <span class="notranslate">`cagefsctl --site-isolation-enable <domain>`</span>. Removing isolation is never gated this way, so any containers created by an earlier version can always be torn down.
+If either package is below the required minimum and a compatible update is available for your OS and panel, update it and re-run <span class="notranslate">`cagefsctl --site-isolation-enable <domain>`</span>. Disabling filesystem isolation does not guarantee cleanup of an existing domain LVE if the panel or running kernel lacks the required capability. If a domain LVE remains, stop and contact support rather than assuming it was removed.
 
 **"No domain limits configured for UID *N*"**
 
 The account exists but has no isolated domains. Enable isolation for a domain first — <span class="notranslate">`cagefsctl --site-isolation-enable <domain>`</span>. A genuinely unknown account reports <span class="notranslate">`UID N does not exist`</span> instead.
 
 **A domain's statistics stopped after a rename or a document root change**
 
 The domain's registry entry is keyed on its document root. Changes made through a supported control panel are handled by the panel hooks; if the change was made outside the panel, refresh the mapping by hand:
 
 ```
diff --git a/docs/cloudlinuxos/limits/README.md b/docs/cloudlinuxos/limits/README.md
index d15a049..9faaf4c 100644
--- a/docs/cloudlinuxos/limits/README.md
+++ b/docs/cloudlinuxos/limits/README.md
@@ -82,45 +82,38 @@ Today, a single site can consume all <span class="notranslate"> CPU, IO, Memory<
 The kernel makes sure that all LVEs get fair share of the server's resources, and that no customer can use more then the limits set for that customer.
 Today we can limit <span class="notranslate">CPU </span>, <span class="notranslate"> Memory </span> (virtual and physical), IO, number of processes as well as the number of entry processes (concurrent connections to apache).
 
 Each LVE limits amount of entry processes (Apache processes entering into LVE) to prevent single site exhausting all Apache processes. If the limit is reached, then <span class="notranslate">mod_hostinglimits</span> will not be able to place Apache process into LVE, and will return error code 508. This way very heavy site would slow down and start returning 508 errors, without affecting other users.
 
 * If the site is limited by <span class="notranslate"> CPU </span> or <span class="notranslate">IO</span>, then the site will start responding slower.
 * If the site is limited by memory or number of processes limits, then the user will receive 500 or 503 errors that server cannot execute the script.
 
 ### Checking if LVE is installed
 
-To use LVE you should have CloudLinux OS kernel installed, and LVE module loaded. You can check the kernel by running the following command:
+To use LVE, the `kmodlve` kernel module must be loaded. The name shown by `uname -r` does not verify whether the LVE module is loaded; check the module directly. On RPM-based systems, check the installed packages and the loaded module:
 
 <div class="notranslate">
 
 ```
-uname -r
+rpm -q lve
+rpm -q --whatprovides kmod-lve
+lsmod | grep '^kmodlve '
 ```
 </div>
 
-You should see something like 2.6.32-896.16.1.lve1.4.53.el6.x86_64. The kernel should have lve in its name. To see if lve kernel module is loaded run:
-
-<div class="notranslate">
-
-```
-lsmod|grep lve
-
-lve                    46496  0
-```
-</div>
+If the module is absent, inspect the `lve.service` logs and check `LVE_ENABLE=yes` in the file the loader uses: `/etc/sysconfig/lve` on RPM-based CloudLinux systems, or `/etc/default/lve` if the first file is absent. A successful service start can also mean that loading was deferred on a kernel that enforces Intel IBT; see [conversion troubleshooting](/cloudlinuxos/cloudlinux_installation/#server-panics-or-reboots-during-conversion-on-intel-cpus-with-ibt).
 
 Starting from kernels lve1.4.x iolimits module is a part of kmod-lve and could not be used separately.
 
-* You can toggle LVE on/off by editing <span class="notranslate">`/etc/sysconfig/lve`</span> and setting <span class="notranslate">`LVE_ENABLE`</span> variable to <span class="notranslate">`yes`</span> or <span class="notranslate">`no`</span>.
+* On RPM-based CloudLinux systems, you can control whether the LVE service attempts to load the module by setting <span class="notranslate">`LVE_ENABLE`</span> in <span class="notranslate">`/etc/sysconfig/lve`</span> to <span class="notranslate">`yes`</span> or <span class="notranslate">`no`</span>. If that file is absent, the loader checks `/etc/default/lve` instead.
 
-    Setting it to <span class="notranslate">`yes`</span> will enable LVE, setting it to <span class="notranslate">`no`</span> will disable LVE.
+    <span class="notranslate">`yes`</span> permits a load when other prerequisites are met; <span class="notranslate">`no`</span> skips the load at service start. After reboot, check that the module is loaded rather than assuming that the setting makes LVE active.
 
 * You can toggle IO limits by editing <span class="notranslate">`/etc/sysconfig/iolimits`</span> and setting <span class="notranslate">`IO_LIMITS_ENABLED`</span> variable to <span class="notranslate">`yes`</span> or <span class="notranslate">`no`</span>.
 
 You need to reboot the server, after you set this option to make the changes live.
 
 ### Controlling LVE limits
 
 The best way to control LVE limits is using <span class="notranslate">LVE Manager</span> in your favorite control panel. Alternatively, you can use command line tool `lvectl` to control limits.
 The limits are saved in <span class="notranslate">`/etc/container/ve.cfg`</span>
 

@NikolayVoina
NikolayVoina deleted the docs-audit/build-5f7ca2852b52 branch September 30, 2026 15:50
@NikolayVoina
NikolayVoina restored the docs-audit/build-5f7ca2852b52 branch September 30, 2026 15:51
@NikolayVoina NikolayVoina reopened this Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant