zededa:zcli-how-to
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| zededa:zcli-how-to [2026/08/20 15:05] – created mc | zededa:zcli-how-to [2026/08/20 15:11] (current) – mc | ||
|---|---|---|---|
| Line 86: | Line 86: | ||
| < | < | ||
| - | zcli edge-node create MY_EDGE_NODE --project=MY_PROJECT | + | zcli edge-node create MY_EDGE_NODE --project=MY_PROJECT |
| + | --network=eth0: | ||
| + | </ | ||
| + | |||
| + | - View it: '' | ||
| + | - Update it later: '' | ||
| + | |||
| + | ===== Adapter-Specific Interface Config ===== | ||
| + | |||
| + | For anything beyond a single static IP, ZCLI uses a JSON template workflow instead of a giant flag list. | ||
| + | |||
| + | - Copy the templates: '' | ||
| + | * Drops '' | ||
| + | - Edit the json file (vi works fine in the container: **i** to insert, **Esc** to stop, **:wq** to save) | ||
| + | - Use it when creating or updating a node: | ||
| + | |||
| + | < | ||
| + | zcli edge-node create MY_EDGE_NODE --project=MY_PROJECT --model=Advantech-2012 \ | ||
| + | --adapter-network-config=adapter-net-config-templates/ | ||
| + | </ | ||
| + | |||
| + | - Pull an existing node's config back out for editing: '' | ||
| + | |||
| + | ===== Day 2 Operations ===== | ||
| + | |||
| + | ^ Task ^ Command ^ | ||
| + | | Reboot | '' | ||
| + | | Graceful shutdown prep | '' | ||
| + | | Deactivate (stops app instances) | '' | ||
| + | | Reactivate | '' | ||
| + | | Update EVE-OS image | '' | ||
| + | | Remove an old EVE-OS image | '' | ||
| + | | Pull current config to a file | '' | ||
| + | | Force a config regen from cloud | '' | ||
| + | | Pull TPM PCR values | '' | ||
| + | | Delete | '' | ||
| + | |||
| + | '' | ||
| + | |||
| + | ===== Output Format ===== | ||
| + | |||
| + | Default output is human-readable text. Force JSON for scripting with the global flag: | ||
| + | |||
| + | < | ||
| + | zcli -o json edge-node show MY_EDGE_NODE | ||
| + | </ | ||
| + | |||
| + | ===== SSH Into an Edge Node via ZCLI ===== | ||
| + | |||
| + | SSH access to EVE-OS is off by default. You turn it on by pushing your public key to the node's '' | ||
| + | |||
| + | ==== Step 1: Get Your Public Key ==== | ||
| + | |||
| + | < | ||
| + | cat ~/ | ||
| + | </ | ||
| + | |||
| + | If that's empty, generate one first: | ||
| + | |||
| + | < | ||
| + | ssh-keygen -b 2048 -t rsa | ||
| + | </ | ||
| + | |||
| + | ==== Step 2: Push the Key to the Edge Node ==== | ||
| + | |||
| + | < | ||
| + | zcli edge-node update EDGE_NODE --config=debug.enable.ssh:" | ||
| + | </ | ||
| + | |||
| + | Or pull the key straight from the file instead of pasting it: | ||
| + | |||
| + | < | ||
| + | zcli edge-node update EDGE_NODE --config=" | ||
| + | </ | ||
| + | |||
| + | Note: this survives until you clear it, but if you re-onboard or re-image the device, the key gets wiped and you'll need to push it again. | ||
| + | |||
| + | ==== Step 3: Find the Node's IP ==== | ||
| + | |||
| + | Pull it from '' | ||
| + | |||
| + | ==== Step 4: SSH In ==== | ||
| + | |||
| + | < | ||
| + | ssh -i ~/ | ||
| + | </ | ||
| + | |||
| + | ==== Step 5: Disable SSH When You're Done ==== | ||
| + | |||
| + | < | ||
| + | zcli edge-node update EDGE_NODE --config=debug.enable.ssh:"" | ||
| + | </ | ||
| + | |||
| + | An empty string clears every authorized key. Verify it actually cleared before you walk away from the box. | ||
| + | |||
| + | ==== Alternative: | ||
| + | |||
| + | ZEDEDA recommends Edge View over raw SSH for production environments. It adds policy control at the node/ | ||
| + | |||
| + | ===== Debug and Troubleshooting Knobs ===== | ||
| + | |||
| + | Same '' | ||
| + | |||
| + | < | ||
| + | zcli edge-node update EDGE_NODE --config=" | ||
| + | </ | ||
| + | |||
| + | Changes sync on the node's next config check (default every 60 seconds, tunable via '' | ||
| + | |||
| + | ^ Knob ^ Type ^ Default ^ What it does ^ | ||
| + | | debug.enable.ssh | SSH pubkey string | "" | ||
| + | | debug.enable.usb | boolean | false | Allows USB devices (keyboards, etc.) on the node | | ||
| + | | debug.enable.vga | boolean | false | Allows VGA console output | | ||
| + | | debug.enable.console | boolean | false | Allows console access to EVE-OS; needs a reboot to turn back off | | ||
| + | | debug.enable.vnc.shim.vm | boolean | false | Allows VNC into the container app shim VM; needs a reboot to turn back off | | ||
| + | |||
| + | A separate, unrelated command turns on raw metrics collection rather than a '' | ||
| + | |||
| + | < | ||
| + | zcli edge-node enable-debug-knob EDGE_NODE [--expiry=< | ||
| + | zcli edge-node disable-debug-knob EDGE_NODE [--expiry=< | ||
| + | </ | ||
| + | |||
| + | That one is specifically for storing raw metrics on the device, don't confuse it with the '' | ||
| + | |||
| + | ===== Storage-Related Knobs (Same --config Pattern) ===== | ||
| + | |||
| + | ^ Knob ^ Type ^ Default ^ What it does ^ | ||
| + | | storage.dom0.disk.minusage.percent | integer | 20 | Minimum percent of the persist partition reserved for the EVE-OS base system | | ||
| + | | storage.zfs.reserved.percent | integer | 20 | Minimum percent of the persist partition reserved for ZFS | | ||
| + | | storage.apps.ignore.disk.check | boolean | false | Lets edge containers create images larger than available disk space, can cause out-of-disk errors, use carefully | | ||
| + | | timer.gc.vdisk | seconds | 3600 | How often EVE-OS garbage collects unused container virtual disks | | ||
| + | | timer.defer.content.delete | seconds | 0 | Keeps deleted content trees around for reuse for this long; 0 deletes immediately | | ||
| + | |||
| + | ===== Mapping a Local Volume to an Edge Node ===== | ||
| + | |||
| + | This is a different thing from the knobs above. A volume instance is persistent or scratch storage you attach to an app running on a specific edge node, not a debug switch. | ||
| + | |||
| + | ==== Create It ==== | ||
| + | |||
| + | < | ||
| + | zcli volume-instance create MY-VOL-INST --volume-type=CONTENT_TREE --project=MY-PROJECT \ | ||
| + | --edge-node=MY-EDGE-NODE --size=100 --access-mode=READWRITE | ||
| + | </ | ||
| + | |||
| + | For an edge node cluster instead of a single node, swap '' | ||
| + | |||
| + | ==== View It ==== | ||
| + | |||
| + | < | ||
| + | zcli volume-instance show --edge-node=MY-EDGE-NODE | ||
| + | </ | ||
| + | |||
| + | ==== Update or Delete ==== | ||
| + | |||
| + | < | ||
| + | zcli volume-instance update MY-VOL-INST --title=NEW-TITLE | ||
| + | zcli volume-instance delete MY-VOL-INST -f | ||
| + | </ | ||
| + | |||
| + | ==== Persistent vs. Perishable ==== | ||
| + | |||
| + | Volume instances are created the same way regardless. What decides persistence is the **Purge** setting on the edge app that consumes the volume: leave Purge unchecked and the volume survives app updates and restarts. Check it, and the volume gets wiped on purge/ | ||
| + | |||
| + | One catch: a persistent volume instance belongs to the specific edge node it was created on. Same behavior on multiple nodes means a separate volume instance per node, it doesn' | ||
| + | |||
| + | ===== Quick Reference: Which Tool for Which Job ===== | ||
| + | |||
| + | ^ Goal ^ Tool ^ | ||
| + | | Get a shell on the node | '' | ||
| + | | Turn on/off USB, VGA, console, VNC shim access | '' | ||
| + | | Turn on raw metrics storage | '' | ||
| + | | Give an app persistent or scratch disk space | '' | ||
| + | | Change storage allocation thresholds device-wide | '' | ||
| + | |||
| + | ===== Gotchas ===== | ||
| + | |||
| + | * Most successful commands print nothing. Silence means it worked, only failures produce output. | ||
| + | * TLS verification is on by default. '' | ||
| + | * The GUI onboarding wizard does more behind the scenes (network + project wiring) than '' | ||
| + | * '' | ||
| + | |||
| + | ===== Source ===== | ||
| + | |||
| + | * ZEDEDA Help Center: " | ||
| + | * ZEDEDA Help Center: "ZCLI: Create and Manage Edge Nodes" | ||
| + | * ZEDEDA Help Center: "How to Enable and Disable SSH for Edge Nodes" | ||
| + | * ZEDEDA Help Center: " | ||
| + | * ZEDEDA Help Center: "ZCLI: Create and Manage Volume Instances" | ||
| + | * ZEDEDA Help Center: "Add Persistent Volume Instances" | ||
zededa/zcli-how-to.1787238356.txt.gz · Last modified: by mc
