zededa:workshop:00_index
This is an old revision of the document!
Table of Contents
ZEDEDA Platform Workshop: EVE-OS and EVE-KVM Workflows
This wiki covers the core ZEDEDA Cloud objects and workflows used to deploy and manage edge workloads. Each section explains what the object is, how to create it via ZEDUI, Terraform, and the API, and what happens on the edge node when the object is applied.
Sections
| # | Topic | Description |
|---|---|---|
| 01 | Projects | Top-level org unit; access control and resource scoping |
| 02 | Datastores | Remote storage backends for images and artifacts |
| 03 | Images | VM disk images and OCI container images |
| 04 | EVE-OS Images | OS firmware for edge node onboarding and upgrades |
| 05 | Patch Envelopes | Inline file and config delivery to running apps |
| 06 | Persistent Volumes and Content Trees | Stateful storage and read-only data distribution |
| 07 | Edge Apps | App Bundles and App Instances; VM and container workloads |
| 08 | Deploying from Marketplace | One-click certified app deployment |
Dependency Order
When setting up a project from scratch, create objects in this order to avoid missing-dependency errors:
- Project (required first; everything else belongs to it)
- Datastores (required before Images and Content Trees)
- Images (required before App Bundles)
- EVE-OS Images (assign to edge nodes before or after project creation)
- Network Instances (required before App Instances; see network documentation)
- Persistent Volumes / Content Trees (can be created in parallel with images)
- Patch Envelopes (optional; add to App Bundle definition)
- App Bundle (references images, volumes, networks, patch envelopes)
- App Instance (deploys the bundle to a specific edge node)
Architecture: How It Flows
ZEDUI / Terraform / API
|
v
ZEDEDA Cloud Controller
(stores config, manages state,
distributes to devices)
|
| HTTPS / mTLS
| (device heartbeat every 60s by default)
v
EVE-OS on Edge Node
(pulls config, downloads images
from datastores, starts workloads
via KVM or containerd)
|
v
Running Workload
(VM via KVM, or OCI container
via containerd)
Key Concepts
- Heartbeat: EVE-OS checks in with the controller on a regular interval (default 60s). Config changes are delivered on the next heartbeat, not pushed in real time.
- Measured Boot: EVE-OS uses TPM-based measured boot to record component state for remote attestation. This is not the same as secure boot (which blocks unsigned code).
- A/B Partitions: EVE-OS updates use a dual-partition scheme. Updates are written to the inactive partition and activated on reboot. The previous partition is retained as a fallback.
- Project Scoping: All ZEDEDA Cloud objects belong to a project. API tokens and user accounts are permissioned at the project level.
zededa/workshop/00_index.1780243443.txt.gz · Last modified: (external edit)
