Running LXC and Full Virtualization on Raspberry Pi 5: KVM vs Docker Containers
This site's Raspberry Pi content covers Docker, Kubernetes with K3s, and Docker Swarm extensively for container-based self-hosting — but containers share the host kernel, which isn't always what you want. The Raspberry Pi 5's Cortex-A76 cores support the ARM virtualization extensions properly for the first time in the Pi line, making real hardware-accelerated KVM virtual machines practical rather than painfully slow software emulation. This guide covers when LXC or KVM actually beats Docker on a Pi 5, and how to set each one up.
Containers, LXC, and KVM: What's Actually Different
DockerLXCKVM Isolation levelProcess + namespaces, shares host kernelFull OS-level container, shares host kernelFull hardware virtualization, separate kernel Can run a different kernel/OSNo (same kernel as host, Linux-only)No (same kernel as host, Linux-only)Yes — a full guest OS, including non-Linux Typical use caseSingle-application services, microservicesFull "VM-feeling" Linux systems with systemd, multiple servicesKernel-level testing, running an incompatible OS, strong isolation Overhead on Pi 5LowestVery low — close to nativeNoticeable but usable; expect 5-15% overhead for most workloadsThe practical rule: if you're deploying one service in one container, Docker is still the right default on a Pi — it's what this site's other self-hosting guides are built around. Reach for LXC when you want something that behaves like a lightweight full Linux machine (its own systemd, multiple cooperating services, SSH access like a real box) without full virtualization overhead. Reach for KVM when you specifically need kernel-level isolation, need to run a different kernel version or OS entirely, or you're testing something where "it's technically still the host kernel" (true of both Docker and LXC) actually matters.
Setting Up LXC
LXC runs fine on Raspberry Pi OS or Ubuntu Server for the Pi. Install it and create a container with the standard tooling:
sudo apt install lxc lxc-templates sudo lxc-create -n my-container -t download sudo lxc-start -n my-container sudo lxc-attach -n my-containerThe download template lets you pick from a list of pre-built images (Debian, Ubuntu, Alpine, and others, all ARM64 builds) rather than building a rootfs by hand. Give the container a static, bridged network config in /var/lib/lxc/my-container/config if you want it reachable on your LAN like any other host rather than NATed behind the Pi.
Setting Up KVM
Check virtualization support first — the Pi 5's firmware and kernel need to expose the ARM virtualization extensions:
ls /dev/kvm cat /proc/cpuinfo | grep Features | grep -o 'vhe\|lpae'If /dev/kvm exists, install the standard libvirt/QEMU stack:
sudo apt install qemu-kvm libvirt-daemon-system libvirt-clients virtinst bridge-utils sudo usermod -aG libvirt,kvm $USERCreate a VM with virt-install or a GUI tool like virt-manager run remotely over SSH with X forwarding (a Pi 5 running headless doesn't need a local display for this — manage it from your main machine). Use an ARM64 guest image — Ubuntu Server for ARM and Debian both publish ready-to-use cloud images — since KVM on a Pi can only accelerate guests matching its own architecture; don't expect to run x86 Windows or an x86 Linux distro at usable speed, that still needs full software emulation (QEMU's TCG mode) and will be dramatically slower than the host.
Performance Expectations
Real-world KVM overhead on a Pi 5 for a Linux-on-Linux ARM64 guest is modest — CPU-bound workloads typically land within 5-15% of bare metal, and disk I/O performance depends heavily on whether you're using virtio drivers (do — they're dramatically faster than emulated IDE/SATA) and whether the backing storage is the Pi's SD card or an NVMe SSD over the PCIe interface. Memory overhead matters more on a Pi than on a server — with 8GB being the largest common Pi 5 configuration, budget guest RAM carefully if you're running more than one or two VMs alongside your host workload.
When to Just Use Docker Instead
If you find yourself setting up an LXC container or KVM VM just to run one web service, a database, or a single self-hosted app — the pattern this site's other Pi guides (Nextcloud, Gitea, Jellyfin, and the rest) all use — stop and use Docker instead. The extra isolation of LXC or KVM is real, but it comes with real setup and maintenance overhead, and for a single-purpose service, a container gives you nearly all the deployment convenience with a fraction of the administrative surface area.
The Pi 5 is the first Raspberry Pi where "run a real VM" is a reasonable sentence rather than a novelty — the virtualization extensions work, KVM is genuinely usable, and LXC has effectively no practical downside over a Docker container when what you actually want is a lightweight full Linux system. Pick the isolation level the workload actually needs rather than defaulting to whichever one you set up most recently.