User Tools

Site Tools


workshop:00_index

ZEDEDA Platform Workshop: EVE-OS and EVE-KVM Workflows

This wiki covers the core ZEDEDA Cloud objects and workflows used to deploy and manage edge workloads on EVE-KVM. Each section explains what the object is, how to create it via ZEDUI, Terraform, and the API, and what happens on the edge node when it is applied.

Sections

# Page Description
01 Projects Top-level org unit; types, policies, Zero-Touch Deployments
02 Datastores Remote storage backends: HTTP, S3, Azure Blob, container registries
03 Images VM disk images and OCI container images
03a Networks EVE-OS control-plane port config: DHCP, static IP, proxy
03b Network Instances App data-plane networking: Switch and Local NIs
04 EVE-OS Images OS firmware for edge nodes; upgrades, variants, cluster upgrades
05 Patch Envelopes Runtime file and config delivery to running apps via metadata server
06 Persistent Volumes and Content Trees Stateful block storage and read-only image-backed volumes
07a Edge Apps App Bundle definitions: manifest, images, interfaces, ACLs, resources
07b App Instances Deploying bundles to nodes: network wiring, cloud-init, SR-IOV
08 Marketplace Importing and deploying Marketplace apps (same flow as App Instances)

Dependency and Creation Order

When setting up a project from scratch, create objects in this order:

  1. Project – everything else belongs to it
  2. Datastores – required before Images and Content Trees
  3. Networks – required before edge nodes can connect (control plane)
  4. Images – required before App Bundles
  5. EVE-OS Images – assign to edge nodes during or after onboarding
  6. Network Instances – required before App Instances (data plane)
  7. Persistent Volumes / Content Trees – create before or alongside App Instances
  8. Patch Envelopes – create before or after App Bundles as needed
  9. App Bundle – references images, declares interface names, resources, ACLs
  10. App Instance – deploys the bundle to a node; wires interfaces to Network Instances

Architecture: How It All Flows

ZEDUI / Terraform / API
        |
        v
ZEDEDA Cloud Controller
(stores config, tracks state,
 distributes to devices)
        |
        | HTTPS / mTLS heartbeat (default 60s)
        |
        v
EVE-OS on Edge Node
(pulls config, downloads images from datastores,
 creates network instances, starts workloads via KVM)
        |
        v
Running Workload
(VM via KVM/QEMU on EVE-KVM,
 or OCI container via containerd)

Key Concepts

  • Heartbeat: EVE-OS checks in with the controller on a regular interval (default 60 seconds). Config changes are delivered at the next heartbeat, not pushed in real time.
  • Measured Boot: EVE-OS uses TPM-based measured boot to record component state for remote attestation. Not the same as secure boot – measured boot records and reports state; it does not block unsigned code.
  • A/B Partitions: EVE-OS updates use a dual-partition scheme. Updates are written to the inactive partition and activated on reboot. The previous partition is kept as a fallback.
  • Network vs Network Instance: A Network configures how a physical port gets its IP (EVE control plane). A Network Instance is a virtual network for app workloads (app data plane).
  • Switch NI vs Local NI: Switch NI is a transparent L2 bridge – apps are on the physical wire. Local NI is a virtual router with EVE-OS running DHCP and NAT.
  • App Bundle vs App Instance: The bundle is the definition (what to run). The instance is the deployment (where to run it, how to wire it).
  • Project Scoping: All objects belong to a project. API tokens and users are permissioned at the project level.
workshop/00_index.txt · Last modified: by mc