zededa:workshop:04_eve_os_images
This is an old revision of the document!
Table of Contents
EVE-OS Images
EVE-OS Images are signed OS firmware images used to onboard new edge nodes or upgrade the EVE-OS version on existing ones. They are distinct from application images: they are the operating system itself, not a workload. ZEDEDA Cloud manages distribution and version tracking; EVE-OS handles the update process on the node using a dual-partition A/B scheme.
What It Is
- Signed OS firmware images for edge nodes running EVE-OS (part of LF Edge)
- Distributed by ZEDEDA Cloud to update or baseline the EVE-OS version on registered devices
- EVE-OS uses an A/B partition scheme: one partition is active, one is the update target
- Integrity is verified via measured boot: component state is recorded via TPM for remote attestation (not secure boot, which blocks unsigned code; measured boot records and reports state)
- The controller tracks the current version per device and the desired version from the assigned EVE-OS image
Flow: ZEDUI to API to Edge Node
ZEDUI
- Navigate to Edge Nodes > EVE Images
- Click Upload EVE Image
- Provide the EVE-OS version string and upload the signed image file
- Once uploaded, navigate to the target Edge Node record
- Under Software, set the desired EVE-OS version
- Save the device config to trigger the update
Terraform
# Register the EVE-OS image
resource "zedcloud_image" "eve_os_image" {
name = "eve-os-10-2-0"
image_type = "IMAGE_TYPE_EVE"
datastore_id = zedcloud_datastore.eve_store.id
image_rel_url = "eve/eve-kvm-10.2.0.img"
image_format = "RAW"
image_sha256 = "def456..."
}
# Assign to an edge node
resource "zedcloud_edgenode" "node01" {
name = "workshop-node-01"
title = "Workshop Node 01"
model_id = var.device_model_id
eve_image_id = zedcloud_image.eve_os_image.id
project_id = zedcloud_project.workshop.id
}
API
# Register the EVE-OS image
POST /v1/images
{
"name": "eve-os-10-2-0",
"imageType": "IMAGE_TYPE_EVE",
"datastoreId": "<datastore_id>",
"imageRelUrl": "eve/eve-kvm-10.2.0.img",
"imageFormat": "RAW",
"imageSha256": "def456..."
}
# Assign to a device
PATCH /v1/devices/{device_id}
{
"eveImageId": "<eve_image_id>"
}
What Happens on the Edge Node
- At the next heartbeat, EVE-OS receives a config update indicating the desired OS version
- EVE-OS compares the desired version to the running version; if different, it initiates a download
- The signed image is downloaded and written to the inactive partition (A/B scheme)
- EVE-OS verifies the image signature before setting the inactive partition as the next boot target
- The node reboots into the new OS partition
- If the new partition fails to check in within a timeout, EVE-OS falls back to the previous partition automatically
- ZEDEDA Cloud updates the device record to reflect the new running version after successful check-in
Related Resources
zededa/workshop/04_eve_os_images.1780243587.txt.gz ยท Last modified: (external edit)
