Prepare Your VM – EderaON

Prepare Your VM

At the end of this guide, you will have a node ready to install Edera.

Get your license

  1. Create an account at on.edera.dev if you don’t have one
  2. Log in and click Create License
  3. Click Show to reveal your license key

Your license key is used during installation to authenticate to the Edera registry.

⚠️

One license key can only be active on one machine at a time. Deactivate your node from the dashboard before reusing a license on a different machine.

System requirements

No UEFI required — any EC2 instance type with hardware virtualization works (t3, m5, m6i, and more).

UEFI boot mode is required. Use a UEFI-capable AMI on EC2 (m5, c5, m6i instance types). Default Ubuntu (24.04 and above) and Amazon Linux (AL2023) AMIs boot UEFI.

Launch a node

EC2 (Script)

Use a setup script to provision an EC2 instance. You can view the full usage details in the edera-dev/learn repository.

ℹ️

Before running the script, make sure you’re authenticated with AWS. Run aws configure (or aws login for SSO) if you haven’t already.

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/edera-dev/learn/refs/heads/main/getting-started/edera-on-installer/scripts/ec2-setup.sh)"

Prerequisites

If you don’t have a key pair:

export KEY_FILE=edera-key.pem
aws ec2 create-key-pair --key-name edera-key --query 'KeyMaterial' --output text > $KEY_FILE
chmod 400 $KEY_FILE

Get your key name

export KEY_NAME=$(aws ec2 describe-key-pairs 
  --query 'KeyPairs[0].KeyName' --output text)

Get your subnet ID

export SUBNET_ID=$(aws ec2 describe-subnets 
  --query 'Subnets[0].SubnetId' --output text)

Set up a security group

export SG_ID=$(aws ec2 create-security-group 
  --group-name ederaon-sg 
  --description "EderaON evaluation" 
  --query 'GroupId' --output text)

aws ec2 authorize-security-group-ingress 
  --group-id $SG_ID 
  --protocol tcp 
  --port 22 
  --cidr $(curl -s https://checkip.amazonaws.com)/32

Launch the instance

aws ec2 run-instances 
  --image-id ami-0d76b909de1a0595d 
  --instance-type m5.large 
  --key-name $KEY_NAME 
  --block-device-mappings "[{\"DeviceName\":\"${ROOT_DEVICE}\",\"Ebs\":{\"VolumeSize\":30,\"VolumeType\":\"gp3\"}}]" 
  --security-group-ids $SG_ID 
  --subnet-id $SUBNET_ID 
  --associate-public-ip-address 
  --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=ederaon-test}]'

ℹ️

The AMI ID above is for us-west-2. Find the latest Ubuntu AMI for your region on Ubuntu Cloud Images.

Connect to your instance

export INSTANCE_IP=$(aws ec2 describe-instances 
  --filters "Name=tag:Name,Values=ederaon-test" 
  --query 'Reservations[*].Instances[*].PublicIpAddress' 
  --output text)

ssh -i $KEY_FILE ubuntu@$INSTANCE_IP

Install dependencies

Install Docker (or Podman on CentOS/RHEL) and nftables on your instance.

Ubuntu:

sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER

Amazon Linux 2023:

sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER

CentOS Stream 9 / RHEL 10:

sudo dnf install -y podman nftables

CentOS and RHEL use Podman instead of Docker. sudo is required with Podman so the installer can write to system directories.

Start a new SSH session after running the usermod command. The group change only takes effect in new sessions.

UEFI boot mode

UEFI is required. Set the firmware to UEFI when creating the VM — this cannot be changed after creation.

In libvirt/virt-manager, set the firmware to UEFI in the VM overview before first boot. In the XML, this looks like:

<os firmware="efi">
  ...
</os>

To verify after boot:

[ -d /sys/firmware/efi ] && echo UEFI || echo BIOS

If this prints BIOS, recreate the VM with UEFI firmware enabled.

Memory

Allocate at least 4 GB RAM to the VM. The installer checks available memory and will fail if less than ~3.8 GB is reported. Hypervisor overhead reduces the amount visible to the guest, so if you allocate exactly 4 GB you may be just under the threshold. Allocate 6-8 GB if possible.

Networking

The VM needs outbound internet access to reach the Edera registry and package servers. If you’re using libvirt’s default NAT network (virbr0), this works out of the box. If you’re using a bridged or isolated network, make sure the VM has a route to the internet before running the installer.

Install system packages

Install Docker (or Podman on CentOS/RHEL) and nftables on your VM.

Ubuntu:

sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER

Amazon Linux 2023:

sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER

CentOS Stream 9 / RHEL 10:

sudo dnf install -y podman nftables

CentOS and RHEL use Podman instead of Docker. sudo is required with Podman so the installer can write to system directories.

Start a new shell session after running the usermod command. The group change only takes effect in new sessions.

Preparing for Kubernetes (optional)

Only needed if you plan to use our Kubernetes bootstrap script in the Run Edera step. If you’re bringing your own Kubernetes cluster (EKS, kubeadm, etc.), skip this — you can configure Edera as the CRI on your existing nodes directly.

Install Kubernetes

sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.36/deb/Release.key \
  | sudo gpg --batch --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.36/deb/ /" \
  | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
sudo systemctl enable --now kubelet

Install Helm

sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://packages.buildkite.com/helm-linux/helm-debian/gpgkey \
  | sudo gpg --batch --dearmor -o /etc/apt/keyrings/helm-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/helm-apt-keyring.gpg] https://packages.buildkite.com/helm-linux/helm-debian/any/ any main" \
  | sudo tee /etc/apt/sources.list.d/helm-stable-debian.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y helm

Configure networking prerequisites

Enable IPv4 forwarding and the processing by iptables of packets traversing a bridge:

echo br_netfilter | sudo tee -a /etc/modules-load.d/99-containerd.conf
sudo systemctl restart systemd-modules-load.service
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
echo 'net.bridge.bridge-nf-call-iptables = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
sudo systemctl restart systemd-sysctl.service

After running these steps, continue to Install Edera. You will bootstrap the cluster in the Run Edera step.