Claiming devices with Edera – Edera

Claiming devices with Edera

3 min read · Advanced


Platform Engineer

Kubernetes users: See Using block devices in Kubernetes instead.

⚠️

PCI device claiming (including GPU passthrough) is only supported on the Xen backend. Block device claiming works on both backends.

This guide covers claiming devices for standalone Edera zones using the protect CLI.

Edera lets you claim and attach physical devices—like block storage or PCI hardware—using a simple config and CLI workflow. This is useful when:

⚠️

Devices are mounted directly into zones and are not virtualized. Use with caution.

TL;DR Permalink for this section

  1. Add device to daemon.toml
  2. Restart the protect daemon
  3. Confirm with protect device list
  4. Use --attach-device on zone launch

Step-by-step Permalink for this section

1. Add the device to the config Permalink for this section

Edit /var/lib/edera/protect/daemon.toml to include your device:

[block.devices]
[block.devices.mydevice]
path = "/dev/sdb" # or your actual device path

For PCI devices (like GPUs or PCI):

[pci.devices]
[pci.devices.pci0]
locations = ["0000:11:00.0"]  # replace with actual PCI address
permissive = true
msi-translate = false
power-management = true
rdm-reserve-policy = "relaxed"

For SR-IOV virtual functions, make sure you add the following options under your individual device configuration (in this case pci0)

skip-pirq-map = true
disable-managed-pciback = true

For now you will also need to hide the device using pciback and blacklist the virtual function driver
For example, edit the /etc/default/grub.d/99-edera-settings.cfg file and add the following to hide two virtual functions and blacklist the iavf driver.

GRUB_CMDLINE_LINUX_DEFAULT="<clipped> xen-pciback.hide=(03:0a.0)(03:0a.1) xen-pciback.passthrough=1 xen-pciback.permissive=1 modprobe.blacklist=iavf"

You can claim multiple devices by adding more entries.

2. Restart the daemon Permalink for this section

sudo systemctl restart protect-daemon

3. Confirm device is available Permalink for this section

protect device list

Make sure mydevice or pci0 appears in the output.

4. Attach the device to a zone Permalink for this section

For block devices:

protect zone launch --name my-zone --attach-scratch-disk mydevice

For PCI devices:

protect zone launch --name my-zone --device pci0

For SR-IOV NIC virtual functions, make sure you use the passthrough network backend

protect zone launch -n test --network-backend passthrough --device pci0

This option is similar to the external backend so you will need to configure the zone networking with

protect zone configure-network <options>

5. Run workloads (optional) Permalink for this section

Once the zone is running, you can launch a workload inside it that uses the device directly:

protect workload launch --zone my-zone --name my-app my-image:latest

Notes Permalink for this section

Further reading Permalink for this section

GPU passthrough to an Edera zone Using a scratch disk with Edera