Boot a VM image as a zone – Edera

Boot a VM image as a zone

Edera zones are normally composed from OCI images. A VM-image zone is a different zone type: it boots an unmodified, UEFI-bootable virtual machine disk image—raw or qcow2—directly, with no repackaging. This lets you run VM-based workloads, such as GPU fleet images or vendor appliances shipped as virtual machines, on Edera without converting them to containers.

⚠️
VM-image zones are an Early Access feature built on the KVM backend. They are not intended for production use and have not completed Edera’s security review.

Prerequisites

Stage the disk image

Copy the image into the daemon’s VM-image directory on the host, /var/lib/edera/protect/vm-images/:

sudo cp jammy-server-cloudimg-amd64.qcow2 /var/lib/edera/protect/vm-images/

The --vm-image flag takes the bare filename of an image in this directory—not a path. Keep the file extension consistent with the format.

Launch the zone

Launch a zone from the staged image with protect zone launch, passing both --vm-image and the required --vm-image-format:

# qcow2 image
protect zone launch \
  --name vm-demo \
  --vm-image jammy-server-cloudimg-amd64.qcow2 \
  --vm-image-format qcow2

For a raw disk image, set the format to raw:

# raw disk image
protect zone launch \
  --name vm-demo \
  --vm-image disk.raw \
  --vm-image-format raw

--vm-image-format is required. Edera does not detect the format automatically.

Verify the zone

Check that the zone reached the ready state:

protect zone list

Once ready, the zone behaves like any other Edera zone. Run a command inside it and read its console logs:

protect zone exec vm-demo hostname
protect zone logs vm-demo

Clean up

Destroy the zone when you’re done. This releases the lock on the image file so it can be reused:

protect zone destroy vm-demo

Requirements and limitations

VM-image zones are validated at launch. Keep these constraints in mind:

Additional resources

Last updated on 2026-07-23