Table of Contents

Sharing a Persistent Volume Between Multiple Apps (ZEDEDA / EVE-OS)

Can a persistent volume be shared by two applications?

Yes. ZEDEDA/EVE-OS supports attaching a single volume instance to multiple application instances via the multiattach flag combined with the MULTIREAD_SINGLEWRITE access mode. Sharing data between edge apps on the same node is one of the documented primary use cases of the storage feature.

This is a supported, real-world pattern: a single block-storage volume (optionally backed by a shared content tree) attached to multiple app instances on one node with multiattach=True.

Access modes

The accessmode field accepts the enum values below. Each is prefixed with VOLUME_INSTANCE_ACCESS_MODE_ (e.g. the full value for “Read-write” is VOLUME_INSTANCE_ACCESS_MODE_READWRITE):

Value (suffix) Meaning
READWRITE Single app, read-write (default for a private volume)
READONLY Read-only
MULTIREAD_SINGLEWRITE Shared — many readers, one writer
INVALID Unset / invalid

To share, use MULTIREAD_SINGLEWRITE and set multiattach = true.

Important constraints

Node storage backend (ZFS vs ext4)

Whether an edge node can honor multi-attach depends entirely on how it backs volumes, which is set by /persist storage type:

Key facts:

Check what a node has: mount | grep /persist (shows zfs or ext4), or zpool status (no pools = not ZFS), via edgeview / SSH.

If the node is ext4 (no ZFS), do not use block-level multi-attach. Instead:

How to: install EVE with a ZFS persist pool

There is no in-place conversion — /persist holds all node state, and its filesystem type is chosen at install / first boot. To get ZFS you must (re)install EVE with ZFS targeted from the start; changing an existing ext4 node means wipe + reinstall + re-onboard.

ZFS is selected via a grub install variable in the installer's grub.cfg (in the config / EFI partition of the install media, or baked into a custom EVE installer image):

eve_install_zfs_with_raid_level=none

Accepted values (default is none):

Value Redundancy ZFS layout / disks needed
none None single disk / stripe — no redundancy (use this for a single-disk box)
raid1 Mirror survives 1 disk loss — needs ≥2 disks
raid5 RAIDZ1 survives 1 disk loss — needs ≥3 disks
raid6 RAIDZ2 survives 2 disk losses — needs ≥4 disks

Notes:

After the ZFS install completes and the node re-onboards, block-storage volumes are zvols and multiattach = true + MULTIREAD_SINGLEWRITE will work.

Do the VMs have to stay one-reader / one-writer?

At any given time only one app may mount the volume read-write; every other app must mount it read-only. A few points that are easy to get wrong:

Rule of thumb:

Terraform (zedcloud provider)

The zedcloud_volume_instance resource exposes both accessmode and multiattach, so this is done entirely in Terraform.

Volume definition

resource "zedcloud_volume_instance" "shared_persist" {
  device_id   = zedcloud_edgenode.my_edgenode.id
  accessmode  = "VOLUME_INSTANCE_ACCESS_MODE_MULTIREAD_SINGLEWRITE"
  multiattach = true
  cleartext   = false
  label       = "shared-persist"
  name        = "shared-persist"
  size_bytes  = 1073741824
  title       = "shared-persist"
  type        = "VOLUME_INSTANCE_TYPE_BLOCKSTORAGE"
  lifecycle {
    ignore_changes = [device_id]
  }
}

Attaching to the writer app (read-write)

  drives {
    imagename   = ""
    volumelabel = zedcloud_volume_instance.shared_persist.label
    mountpath   = "/data"
    cleartext   = false
    ignorepurge = true
    maxsize     = 1073741824
    preserve    = true
    target      = "Disk"
    drvtype     = "HDD"
    readonly    = false   ### writer
  }

Attaching to the reader app(s) (read-only)

  drives {
    imagename   = ""
    volumelabel = zedcloud_volume_instance.shared_persist.label
    mountpath   = "/data"
    cleartext   = false
    ignorepurge = true
    maxsize     = 1073741824
    preserve    = true
    target      = "Disk"
    drvtype     = "HDD"
    readonly    = true    ### reader
  }

Changing the writer (flipping the read/write flags)

Handing the writer role from one app to another is an in-place update of the app instance config — not a recreate.

The Terraform operation

  1. Edit the readonly values on the two drives{} blocks (old writer → true, new writer → false).
  2. terraform plan — you should see ~ update in-place on both zedcloud_application_instance resources (a nested-attribute change), not -/+ replace. If plan shows a replace, stop and investigate.
  3. terraform apply — the provider issues a PUT/update to each app instance, bumping the EdgeAppInstance config version. The controller pushes the new config to the edge node and EVE reconciles.

What happens on the device

The readonly attribute is bound into the VM's disk definition at domain (libvirt) creation time — it is not a live/hot change. EVE cannot just remount; it will restart the affected app instance(s) to bring the disk up in the new mode. Expect a brief VM restart on each VM whose flag changed.

Ordering matters

Because MULTIREAD_SINGLEWRITE allows at most one RW mount at a time, avoid any window where the old writer is still RW while the new writer comes up RW.

This guarantees the volume is never mounted RW by two VMs at once.

Notes

Doing it via zcli / REST API / WebUI

The same two operations — (a) creating/setting the shared volume (accessmode + multiattach) and (b) the writer flip (per-drive readonly on the app instance) — can be done through any interface. The underlying behavior is identical to Terraform.

REST API

Base: https://<zedcontrol>/api — Bearer token in the Authorization header.

Volume (create/update):

Writer flip (app instance) — read-modify-write:

  1. GET /api/v1/apps/instances/id/{id} — get the current config object
  2. In the JSON, edit the target drives[] entry's readonly field (old writer → true, new writer → false)
  3. PUT /api/v1/apps/instances/id/{id} with the full modified object (bumps config version)
  4. Device reconciles; optionally force with PUT /api/v1/apps/instances/id/{id}/restart

A …/refresh/purge endpoint exists too, but for a readonly change a plain PUT + restart is enough — no purge needed.

zcli

zcli manages the same objects: zcli volume-instance … and zcli edge-app-instance ….

Verify exact flag names with zcli volume-instance create –help and zcli edge-app-instance update –help — the per-drive flip is least ergonomic here; WebUI / REST / Terraform are cleaner.

WebUI (zedcontrol console)

Common to all interfaces

Regardless of interface (including Terraform), the underlying behavior is identical:

Common mistake

Referencing the same volume from two app instances while the volume is still defined as plain VOLUME_INSTANCE_ACCESS_MODE_READWRITE with no multiattach is not a valid shared config — it either fails to attach to the second app or produces two uncoordinated read-write mounts. Always set multiattach = true + MULTIREAD_SINGLEWRITE, and keep only one writer.

Summary