Btw, the qemu command generated by libvirt is this one, sorry about that:
2017-03-31 17:40:10.956+0000: starting up libvirt version: 1.3.4, package:
0+amos3~u16.04 (Enea Armband Devops Team <armb...@enea.com> Fri, 13 Jan 2017
02:06:05 +0100), qemu version: 2.8.50(Debian 1:2.9+amos2~u16.04), hostname:
node-2.domain.tld
LC_ALL=C PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
QEMU_AUDIO_DRV=none /usr/bin/kvm -name instance-00000076,debug-threads=on -S
-object
secret,id=masterKey0,format=raw,file=/var/lib/libvirt/qemu/domain-14-instance-00000076/master-key.aes
-machine virt-2.8,accel=kvm,usb=off,gic-version=3 -cpu host -m 256 -realtime
mlock=off -smp 1,sockets=1,cores=1,threads=1 -uuid
2812f3c9-f564-499b-a8c7-e9e7ccf24143 -no-user-config -nodefaults -chardev
socket,id=charmonitor,path=/var/lib/libvirt/qemu/domain-14-instance-00000076/monitor.sock,server,nowait
-mon chardev=charmonitor,id=monitor,mode=control -rtc base=utc,driftfix=slew
-no-shutdown -boot strict=on -kernel
/var/lib/nova/instances/2812f3c9-f564-499b-a8c7-e9e7ccf24143/kernel -initrd
/var/lib/nova/instances/2812f3c9-f564-499b-a8c7-e9e7ccf24143/ramdisk -append
'root=/dev/vda1 rw rootwait console=tty0 console=ttyS0 console=ttyAMA0' -device
i82801b11-bridge,id=pci.1,bus=pcie.0,addr=0x1 -device
pci-bridge,chassis_nr=2,id=pci.2,bus=pci.1,addr=0x0 -usb -drive
file=/var/lib/nova/instances/2812f3c9-f564-499b-a8c7-e9e7ccf24143/disk,format=qcow2,if=none,id=drive-virtio-disk0,cache=none,aio=native
-device
virtio-blk-device,scsi=off,drive=drive-virtio-disk0,id=virtio-disk0,bootindex=1
-drive
file=/var/lib/nova/instances/2812f3c9-f564-499b-a8c7-e9e7ccf24143/disk.config,format=raw,if=none,id=drive-virtio-disk1,cache=none,aio=native
-device virtio-blk-device,scsi=off,drive=drive-virtio-disk1,id=virtio-disk1
-netdev tap,fd=27,id=hostnet0 -device
virtio-net-device,netdev=hostnet0,id=net0,mac=fa:16:3e:82:0a:2b -serial
file:/var/lib/nova/instances/2812f3c9-f564-499b-a8c7-e9e7ccf24143/console.log
-serial pty -vnc 0.0.0.0:0 -k en-us -device
VGA,id=video0,vgamem_mb=16,bus=pci.2,addr=0x1 -device
virtio-balloon-device,id=balloon0 -msg timestamp=on
Domain id=14 is tainted: high-privileges