How Edera’s components fit together – Edera

How Edera’s components fit together

Edera’s hardened runtime layers a Xen-based hypervisor with a host kernel (Dom0), zone kernels (domU), and a set of focused user-space daemons (daemon, storage, network, etc.). This guide walks through each component, how they interact on real systems.

Component map (at a glance)

The full Edera startup sequence. Click to enlarge.

Zones vs. Workloads

A lightweight VM (PVH/PV guest) with its own kernel, launched and managed by Edera. Zones are the unit of isolation—they hold resources like CPU, memory, and network devices. Think of a zone as the “execution sandbox.”

An OCI image that runs inside a zone. When you launch a workload (protect workload launch --zone <ZONE> <OCI>), the daemon pulls the image, hands it to the zone over IDM, and Styrolite starts it as a process with the requested resources.

Hypervisor & kernels

Xen-OCI (hypervisor)

Host kernel (Dom0)

Dom0 startup sequence. Click to enlarge.

Zone kernel (domU)

The Zone startup sequence. Click to enlarge.

Zone memory overhead

Each zone includes a dedicated kernel with fixed memory overhead. When sizing zones, account for this baseline before allocating memory to workloads:

Component Size (MiB) Source
Kernel text/data/rodata ~36 bzImage decompressed (~2.5x ratio)
Kernel dynamic memory ~20 /proc/meminfo (Slab + KernelStack + PageTables + VmallocUsed)
Initramfs/addons ~6 Addons squashfs + boot artifacts
Kernel total ~62 Measured 62.09 MiB
Xen hypervisor 2 Fixed overhead
Total overhead ~64 Measured 64.09 MiB

When configuring zone memory limits, add ~64 MiB to your workload’s requirements. For example, a workload needing 2 GB should have a zone with at least 2.064 GB allocated.

User-space daemons

Daemon (the brain)

Styrolite (inside the zone)

Think of Styrolite as the “container runtime” inside the zone.

The daemon translates configs → IDM, Styrolite interprets them and actually starts the workload.

Storage

Network

Orchestrator and CRI

IDM (Inter-Domain Messaging)

Metrics under the hypervisor section of the /metrics tree do not arrive over IDM—they’re queried from Xen separately.

Audience & expectations

This deep dive assumes the reader already knows about container isolation, Xen, and PCIe.

If you’re earlier in the journey, read the Architecture Overview first, then come back here.