# Prepare Your VM

At the end of this guide, you will have a node ready to install Edera.

## Get your license

1. Create an account at [on.edera.dev](https://on.edera.dev/) if you don’t have one
2. Log in and click **Create License**
3. Click **Show** to reveal your license key

Your license key is used during installation to authenticate to the Edera registry.

⚠️

One license key can only be active on one machine at a time. Deactivate your node from the [dashboard](https://on.edera.dev/) before reusing a license on a different machine.

## System requirements

- **RAM**: 4 GB minimum
- **Disk**: 30 GB minimum
- **Virtualization**: Hardware virt. enabled
- **Boot mode**: UEFI required
- **Container runtime**: Docker (or Podman on CentOS/RHEL)
- **OS**: Ubuntu 24.04+, Amazon Linux 2023, CentOS Stream 9, RHEL 10

No UEFI required — any EC2 instance type with hardware virtualization works (t3, m5, m6i, and more).

UEFI boot mode is required. Use a UEFI-capable AMI on EC2 (m5, c5, m6i instance types). Default Ubuntu (24.04 and above) and Amazon Linux (AL2023) AMIs boot UEFI.

## Launch a node

### EC2 (Script)
Use a setup script to provision an EC2 instance. You can view the full usage details in the [edera-dev/learn repository](https://github.com/edera-dev/learn/tree/main/getting-started/edera-on-installer#ec2-setupsh).

ℹ️

Before running the script, make sure you’re authenticated with AWS. Run `aws configure` (or `aws login` for SSO) if you haven’t already.

```bash
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/edera-dev/learn/refs/heads/main/getting-started/edera-on-installer/scripts/ec2-setup.sh)"
```

### Prerequisites

- [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) installed and configured
- An SSH key pair in your target region

If you don’t have a key pair:

```bash
export KEY_FILE=edera-key.pem
aws ec2 create-key-pair --key-name edera-key --query 'KeyMaterial' --output text > $KEY_FILE
chmod 400 $KEY_FILE
```

### Get your key name

```bash
export KEY_NAME=$(aws ec2 describe-key-pairs 
  --query 'KeyPairs[0].KeyName' --output text)
```

### Get your subnet ID

```bash
export SUBNET_ID=$(aws ec2 describe-subnets 
  --query 'Subnets[0].SubnetId' --output text)
```

### Set up a security group

```bash
export SG_ID=$(aws ec2 create-security-group 
  --group-name ederaon-sg 
  --description "EderaON evaluation" 
  --query 'GroupId' --output text)

aws ec2 authorize-security-group-ingress 
  --group-id $SG_ID 
  --protocol tcp 
  --port 22 
  --cidr $(curl -s https://checkip.amazonaws.com)/32
```

### Launch the instance

```bash
aws ec2 run-instances 
  --image-id ami-0d76b909de1a0595d 
  --instance-type m5.large 
  --key-name $KEY_NAME 
  --block-device-mappings "[{\"DeviceName\":\"${ROOT_DEVICE}\",\"Ebs\":{\"VolumeSize\":30,\"VolumeType\":\"gp3\"}}]" 
  --security-group-ids $SG_ID 
  --subnet-id $SUBNET_ID 
  --associate-public-ip-address 
  --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=ederaon-test}]'
```

ℹ️

The AMI ID above is for `us-west-2`. Find the latest Ubuntu AMI for your region on [Ubuntu Cloud Images](https://cloud-images.ubuntu.com/locator/ec2/).

### Connect to your instance

```bash
export INSTANCE_IP=$(aws ec2 describe-instances 
  --filters "Name=tag:Name,Values=ederaon-test" 
  --query 'Reservations[*].Instances[*].PublicIpAddress' 
  --output text)

ssh -i $KEY_FILE ubuntu@$INSTANCE_IP
```

### Install dependencies

Install Docker (or Podman on CentOS/RHEL) and nftables on your instance.

#### Ubuntu:

```bash
sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
```

#### Amazon Linux 2023:

```bash
sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
```

#### CentOS Stream 9 / RHEL 10:

```bash
sudo dnf install -y podman nftables
```

CentOS and RHEL use Podman instead of Docker. `sudo` is required with Podman so the installer can write to system directories.

**Start a new SSH session after running the usermod command.** The group change only takes effect in new sessions.

### UEFI boot mode

UEFI is required. Set the firmware to UEFI when creating the VM — this cannot be changed after creation.

In libvirt/virt-manager, set the firmware to **UEFI** in the VM overview before first boot. In the XML, this looks like:

```xml
<os firmware="efi">
  ...
</os>
```

To verify after boot:

```bash
[ -d /sys/firmware/efi ] && echo UEFI || echo BIOS
```

If this prints `BIOS`, recreate the VM with UEFI firmware enabled.

### Memory

Allocate at least **4 GB RAM** to the VM. The installer checks available memory and will fail if less than ~3.8 GB is reported. Hypervisor overhead reduces the amount visible to the guest, so if you allocate exactly 4 GB you may be just under the threshold. Allocate 6-8 GB if possible.

### Networking

The VM needs outbound internet access to reach the Edera registry and package servers. If you’re using libvirt’s default NAT network (`virbr0`), this works out of the box. If you’re using a bridged or isolated network, make sure the VM has a route to the internet before running the installer.

### Install system packages

Install Docker (or Podman on CentOS/RHEL) and nftables on your VM.

#### Ubuntu:

```bash
sudo apt-get update && sudo apt-get install -y docker.io nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
```

#### Amazon Linux 2023:

```bash
sudo dnf install -y docker nftables
sudo systemctl start docker
sudo usermod -aG docker $USER
```

#### CentOS Stream 9 / RHEL 10:

```bash
sudo dnf install -y podman nftables
```

CentOS and RHEL use Podman instead of Docker. `sudo` is required with Podman so the installer can write to system directories.

**Start a new shell session after running the usermod command.** The group change only takes effect in new sessions.

## Preparing for Kubernetes (optional)

**Only needed if you plan to use our Kubernetes bootstrap script in the Run Edera step.** If you’re bringing your own Kubernetes cluster (EKS, kubeadm, etc.), skip this — you can configure Edera as the CRI on your existing nodes directly.

### Install Kubernetes

```bash
sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.36/deb/Release.key \
  | sudo gpg --batch --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.36/deb/ /" \
  | sudo tee /etc/apt/sources.list.d/kubernetes.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y kubelet kubeadm kubectl
sudo apt-mark hold kubelet kubeadm kubectl
sudo systemctl enable --now kubelet
```

### Install Helm

```bash
sudo apt-get update -y
sudo apt-get install -y apt-transport-https ca-certificates curl gpg
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://packages.buildkite.com/helm-linux/helm-debian/gpgkey \
  | sudo gpg --batch --dearmor -o /etc/apt/keyrings/helm-apt-keyring.gpg
echo "deb [signed-by=/etc/apt/keyrings/helm-apt-keyring.gpg] https://packages.buildkite.com/helm-linux/helm-debian/any/ any main" \
  | sudo tee /etc/apt/sources.list.d/helm-stable-debian.list
sudo apt-get update -y
sudo DEBIAN_FRONTEND=noninteractive apt-get install -y helm
```

### Configure networking prerequisites

Enable IPv4 forwarding and the processing by `iptables` of packets traversing a bridge:

```bash
echo br_netfilter | sudo tee -a /etc/modules-load.d/99-containerd.conf
sudo systemctl restart systemd-modules-load.service
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
echo 'net.bridge.bridge-nf-call-iptables = 1' | sudo tee -a /etc/sysctl.d/99-kubernetes.conf
sudo systemctl restart systemd-sysctl.service
```

After running these steps, continue to _Install Edera_. You will bootstrap the cluster in the _Run Edera_ step.
