Prepare Your VM – EderaON
Prepare Your VM
At the end of this guide, you will have a node ready to install Edera.
Get your license
- Create an account at on.edera.dev if you don’t have one
- Log in and click Create License
- Click Show to reveal your license key
Your license key is used during installation to authenticate to the Edera registry.
⚠️
One license key can only be active on one machine at a time. Deactivate your node from the dashboard before reusing a license on a different machine.
System requirements
- RAM: 4 GB minimum
- Disk: 30 GB minimum
- Virtualization: Hardware virt. enabled
- Boot mode: UEFI required
- Container runtime: Docker (or Podman on CentOS/RHEL)
- OS: Ubuntu 24.04+, Amazon Linux 2023, CentOS Stream 9, RHEL 10
No UEFI required — any EC2 instance type with hardware virtualization works (t3, m5, m6i, and more).
UEFI boot mode is required. Use a UEFI-capable AMI on EC2 (m5, c5, m6i instance types). Default Ubuntu (24.04 and above) and Amazon Linux (AL2023) AMIs boot UEFI.
Launch a node
EC2 (Script)
Use a setup script to provision an EC2 instance. You can view the full usage details in the edera-dev/learn repository.
ℹ️
Before running the script, make sure you’re authenticated with AWS. Run aws configure (or aws login for SSO) if you haven’t already.
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/edera-dev/learn/refs/heads/main/getting-started/edera-on-installer/scripts/ec2-setup.sh)"
Prerequisites
- AWS CLI installed and configured
- An SSH key pair in your target region
If you don’t have a key pair:
export KEY_FILE=edera-key.pem
aws ec2 create-key-pair --key-name edera-key --query 'KeyMaterial' --output text > $KEY_FILE
chmod 400 $KEY_FILE
Get your key name
export KEY_NAME=$(aws ec2 describe-key-pairs
--query 'KeyPairs[0].KeyName' --output text)
Get your subnet ID
export SUBNET_ID=$(aws ec2 describe-subnets
--query 'Subnets[0].SubnetId' --output text)
Set up a security group
export SG_ID=$(aws ec2 create-security-group
--group-name ederaon-sg
--description "EderaON evaluation"
--query 'GroupId' --output text)
aws ec2 authorize-security-group-ingress
--group-id $SG_ID
--protocol tcp
--port 22
--cidr $(curl -s https://checkip.amazonaws.com)/32
Launch the instance
aws ec2 run-instances
--image-id ami-0d76b909de1a0595d
--instance-type m5.large
--key-name $KEY_NAME
--block-device-mappings "[{\"DeviceName\":\"${ROOT_DEVICE}\",\"Ebs\":{\"VolumeSize\":30,\"VolumeType\":\"gp3\"}}]"
--security-group-ids $SG_ID
--subnet-id $SUBNET_ID
--associate-public-ip-address
--tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=ederaon-test}]'
ℹ️
The AMI ID above is for us-west-2. Find the latest Ubuntu AMI for your region on Ubuntu Cloud Images.
Connect to your instance
export INSTANCE_IP=$(aws ec2 describe-instances
--filters "Name=tag:Name,Values=ederaon-test"
--query 'Reservations[*].Instances[*].PublicIpAddress'
--output text)
ssh -i $KEY_FILE ubuntu@$INSTANCE_IP
Install dependencies
Install Docker (or Podman on CentOS/RHEL) and nftables on your instance.
Ubuntu:
sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
Amazon Linux 2023:
sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
CentOS Stream 9 / RHEL 10:
sudo dnf install -y podman nftables
CentOS and RHEL use Podman instead of Docker. sudo is required with Podman so the installer can write to system directories.
Start a new SSH session after running the usermod command. The group change only takes effect in new sessions.
UEFI boot mode
UEFI is required. Set the firmware to UEFI when creating the VM — this cannot be changed after creation.
In libvirt/virt-manager, set the firmware to UEFI in the VM overview before first boot. In the XML, this looks like:
<os firmware="efi">
...
</os>
To verify after boot:
[ -d /sys/firmware/efi ] && echo UEFI || echo BIOS
If this prints BIOS, recreate the VM with UEFI firmware enabled.
Memory
Allocate at least 4 GB RAM to the VM. The installer checks available memory and will fail if less than ~3.8 GB is reported. Hypervisor overhead reduces the amount visible to the guest, so if you allocate exactly 4 GB you may be just under the threshold. Allocate 6-8 GB if possible.
Networking
The VM needs outbound internet access to reach the Edera registry and package servers. If you’re using libvirt’s default NAT network (virbr0), this works out of the box. If you’re using a bridged or isolated network, make sure the VM has a route to the internet before running the installer.
Install system packages
Install Docker (or Podman on CentOS/RHEL) and nftables on your VM.
Ubuntu:
sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
Amazon Linux 2023:
sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
CentOS Stream 9 / RHEL 10:
sudo dnf install -y podman nftables
CentOS and RHEL use Podman instead of Docker. sudo is required with Podman so the installer can write to system directories.
Start a new shell session after running the usermod command. The group change only takes effect in new sessions.
Preparing for Kubernetes (optional)
Only needed if you plan to use our Kubernetes bootstrap script in the Run Edera step. If you’re bringing your own Kubernetes cluster (EKS, kubeadm, etc.), skip this — you can configure Edera as the CRI on your existing nodes directly.
Install Kubernetes
sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.36/deb/Release.key \
| sudo gpg --batch --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.36/deb/ /" \
| sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
sudo systemctl enable --now kubelet
Install Helm
sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://packages.buildkite.com/helm-linux/helm-debian/gpgkey \
| sudo gpg --batch --dearmor -o /etc/apt/keyrings/helm-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/helm-apt-keyring.gpg] https://packages.buildkite.com/helm-linux/helm-debian/any/ any main" \
| sudo tee /etc/apt/sources.list.d/helm-stable-debian.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y helm
Configure networking prerequisites
Enable IPv4 forwarding and the processing by iptables of packets traversing a bridge:
echo br_netfilter | sudo tee -a /etc/modules-load.d/99-containerd.conf
sudo systemctl restart systemd-modules-load.service
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
echo 'net.bridge.bridge-nf-call-iptables = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
sudo systemctl restart systemd-sysctl.service
After running these steps, continue to Install Edera. You will bootstrap the cluster in the Run Edera step.