# edera.dev > AI-optimized mirror of edera.dev containing 318 pages totalling 0177472061910686411801022816961851013106113144212454947887432733134437108320828901792130696895551084073876411768116233681255551797071197850971319134018551396198338257989180373914317145763457251573715157112827943077121318091120812140233211495912512983953882120266821291591385133526595832218912362875506442873581541272781026838371910324673312923154462975477952091012175959431411991247650637109846446917037448587991316455165823666285079287392410309640601272876105439017151817031250860754429550132128439515171889114711890131164951510001201109449985830730429122267510775446068682132105245379167370116061128071129120076789042988041505371674531101818499954114423111335133848151361911681296215761515408711712616611431511642061028661873807156959882102175884571827442673771428617106166953811644091193124692880194341852335267468589117391117362177023851129471146955283330536551992297334156352457432199374263712382993545236924221669357623100842454704386131059168126663838620117973643347271854447834492520651464 words of clean markdown content, structured data, and semantic HTML. Original source: https://edera.dev. Last updated: 2026-07-29T09:33:31.934Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [ Edera | Trust Center ](/content/trust/index.html) (1,669 words) - [Edera](/content/docs/index.html): Secure-by-design AI and Kubernetes, no matter where you run your infrastructure., Run with Edera. Build with confidence. This is your home for everything Edera—from how-to guides and deep-dive technical overviews to configuration tips and troubleshooting workflows. Whether you’re deploying Edera on Kubernetes or securing your AI infrastructure, these docs give you the clarity and context to do it right. Overview Getting started How-to guides Technical Overview Reference Get support Popular guides Install with edera-installer Install on AWS EKS Install on GCE Falco integration NVIDIA GPU passthrough (75 words) - [EderaON](/content/on/index.html): EderaON — One-node access to hardened runtime protection, Welcome back One-Node License Get a free license to experience Edera's hardened runtime protection firsthand. Create License One-Node License Show License Key Authenticate Before you install → Deactivate Node Your 90-day trial has ended. (79 words) - [Edera Demo Portal](/content/demo/index.html) (12 words) - [Edera | Meet Hardened Runtime](/content/site-root.html): Edera redefines container infrastructure with hardened runtime isolation. Secure, efficient, and simple by design. Where containers meet their full potential. (685 words) ## Articles & Blog Posts - [CLI v1.10.0 – Edera](/content/docs/reference/cli/v1-10-0.html): v1.10.0 (Latest) CLI Version v1.10.0 (Latest) ✓ v1.6.0 v1.3.0 v0.0.1 Using the CLI Control the Edera Protect daemon., v1.10.0 (Latest) CLI Version v1.10.0 (Latest) ✓ v1.6.0 v1.3.0 v0.0.1 Using the CLI Control the Edera Protect daemon. (2659 words) - [CVE-2026-5747: Why VMM Attack Surfaces Can't Be Patched Away](/content/stories/minimal-is-no-longer-enough-why-ai-scale-vulnerability-discovery-changes-container-security.html): Why AI-assisted vulnerability discovery makes VMM attack surfaces structurally unpatachable — and what no-VMM architecture means for container isolation. (3,191 words) - [CLI v1.3.0 – Edera](/content/docs/reference/cli/v1-3-0.html): v1.3.0 CLI Version v1.10.0 (Latest) v1.6.0 v1.3.0 ✓ v0.0.1 ⚠️ The Edera Protect CLI is under active development. Options, Commands and Subcommands are subject to change. Using the CLI Control the Edera Protect daemon., v1.3.0 CLI Version v1.10.0 (Latest) v1.6.0 v1.3.0 ✓ v0.0.1 ⚠️ The Edera Protect CLI is under active development. Options, Commands and Subcommands are subject to change. Using the CLI Control the Edera Protect daemon. (1993 words) - [protect host – Edera](/content/docs/reference/cli/v0-0-1/host/index.html): Manage the host of Edera Protect. protect host Commands: cpu-topology Display information about the host CPU topology. status Get information about the host. idm-snoop Snoop on the IDM bus. hv-console Display hypervisor console output. hv-debug-info Read hypervisor debug information. cpu-topology Display information about the host CPU topology., Manage the host of Edera Protect. protect host Commands: cpu-topology Display information about the host CPU topology. status Get information about the host. idm-snoop Snoop on the IDM bus. hv-console Display hypervisor console output. hv-debug-info Read hypervisor debug information. cpu-topology Display information about the host CPU topology. (132 words) - [protect zone – Edera](/content/docs/reference/cli/v0-0-1/zone/index.html): Manage the zones. protect zone Commands: attach Attach to the zone console. list List zone information. launch Launch a new zone. destroy Destroy a zone. exec Execute a command inside the zone. logs View the logs of a zone. metrics Read metrics from the zone. top Dashboard for running zones. watch Watch for zone changes. update-resources Update the available resources to a zone. attach protect zone attach Arguments:, Manage the zones. protect zone Commands: attach Attach to the zone console. list List zone information. launch Launch a new zone. destroy Destroy a zone. exec Execute a command inside the zone. logs View the logs of a zone. metrics Read metrics from the zone. top Dashboard for running zones. watch Watch for zone changes. update-resources Update the available resources to a zone. attach protect zone attach Arguments: (637 words) - [CLI v1.6.0 – Edera](/content/docs/reference/cli/v1-6-0.html): v1.6.0 CLI Version v1.10.0 (Latest) v1.6.0 ✓ v1.3.0 v0.0.1 Using the CLI Control the Edera Protect daemon., v1.6.0 CLI Version v1.10.0 (Latest) v1.6.0 ✓ v1.3.0 v0.0.1 Using the CLI Control the Edera Protect daemon. (2157 words) - [protect workload – Edera](/content/docs/reference/cli/v0-0-1/workload/index.html): Manage the workloads protect workload Commands: launch Launch a new workload. exec Execute a command inside the workload. attach Attach to a workload console. start Start a workload. stop Stop a workload. destroy Destroy a workload. list List workload information. watch Watch for workload changes. launch protect workload launch [OPTIONS] --zone [COMMAND]... Arguments:, Manage the workloads protect workload Commands: launch Launch a new workload. exec Execute a command inside the workload. attach Attach to a workload console. start Start a workload. stop Stop a workload. destroy Destroy a workload. list List workload information. watch Watch for workload changes. launch protect workload launch [OPTIONS] --zone [COMMAND]... Arguments: (447 words) - [protect image – Edera](/content/docs/reference/cli/v0-0-1/image/index.html): Manage the images. protect image Commands: pull Pull an image into the cache. import Import an image into the cache. remove Remove an image from the cache. list List cached images. pull Pull an image into the cache., Manage the images. protect image Commands: pull Pull an image into the cache. import Import an image into the cache. remove Remove an image from the cache. list List cached images. pull Pull an image into the cache. (179 words) - [protect network – Edera](/content/docs/reference/cli/v0-0-1/network/index.html): Manage the network. protect network Commands: reservation Manage network reservations. reservation protect network reservation Commands:, Manage the network. protect network Commands: reservation Manage network reservations. reservation protect network reservation Commands: (81 words) - [protect device – Edera](/content/docs/reference/cli/v0-0-1/device/index.html): Manage the devices. protect device Commands: list List device information. list List device information. protect device list [OPTIONS] Options:, Manage the devices. protect device Commands: list List device information. list List device information. protect device list [OPTIONS] Options: (36 words) - [Metrics v1.10.0 – Edera](/content/docs/reference/observability/metrics/v1-10-0.html): v1.10.0 (Latest) METRICS v1.10.0 (Latest) ✓ v1.8.4 v1.7.0 v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Collect metrics Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. These metrics are exposed by in the Prometheus format, by default on http://127.0.0.1:3035/., v1.10.0 (Latest) METRICS v1.10.0 (Latest) ✓ v1.8.4 v1.7.0 v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Collect metrics Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. These metrics are exposed by in the Prometheus format, by default on http://127.0.0.1:3035/. (1061 words) - [Zone security model – Edera](/content/docs/technical-overview/security/security-model/index.html): TL;DR Edera isolates workloads inside zones—each zone runs its own Linux kernel inside a hardware-enforced boundary. Edera’s security promise is that code running inside a zone cannot escape the zone to reach the host node or other zones. The configuration that creates the zone—whether a Kubernetes pod spec or a protect CLI command—is outside Edera’s security boundary. Operators are responsible for ensuring that zone configurations do not undermine isolation., TL;DR Edera isolates workloads inside zones—each zone runs its own Linux kernel inside a hardware-enforced boundary. Edera’s security promise is that code running inside a zone cannot escape the zone to reach the host node or other zones. The configuration that creates the zone—whether a Kubernetes pod spec or a protect CLI command—is outside Edera’s security boundary. Operators are responsible for ensuring that zone configurations do not undermine isolation. (1792 words) - [protect completion – Edera](/content/docs/reference/cli/v0-0-1/completion/index.html): Output shell completion code for the specified shell. protect completion ```bash Arguments: - `` Possible values: `bash`, `elvish`, `fish`, `powershell`, `zsh`. , Output shell completion code for the specified shell. protect completion ```bash Arguments: - `` Possible values: `bash`, `elvish`, `fish`, `powershell`, `zsh`. (22 words) - [Securing Edera – Edera](/content/docs/guides/security/harden-for-production/index.html): Step-by-step guide to applying pod security policies, network policies, RBAC, secrets management, and monitoring for a production Edera deployment., Step-by-step guide to applying pod security policies, network policies, RBAC, secrets management, and monitoring for a production Edera deployment. (1298 words) - [Run Edera – EderaON](/content/on/run-edera/index.html): At the end of this guide, you will have launched an isolated zone and run a workload inside it. EC2Kubernetes Launch a zone Launching a zone typically takes less than a minute. If it takes longer, check logs with sudo journalctl -u protect-daemon -n 50., At the end of this guide, you will have launched an isolated zone and run a workload inside it. EC2Kubernetes Launch a zone Launching a zone typically takes less than a minute. If it takes longer, check logs with sudo journalctl -u protect-daemon -n 50. (807 words) - [Prepare Your VM – EderaON](/content/on/prepare-your-vm/index.html): At the end of this guide, you will have a node ready to install Edera. Get your license Create an account at on.edera.dev if you don’t have one Log in and click Create License Click Show to reveal your license key Your license key is used during installation to authenticate to the Edera registry. ⚠️ One license key can only be active on one machine at a time. Deactivate your node from the dashboard before reusing a license on a different machine. System requirements RAM 4 GB minimum Disk 30 GB minimum Virtualization Hardware virt. enabled Boot mode UEFI required Container runtime Docker (or Podman on CentOS/RHEL) OS Ubuntu 24.04+, Amazon Linux 2023, CentOS Stream 9, RHEL 10 No UEFI required — any EC2 instance type with hardware virtualization works (t3, m5, m6i, and more)., At the end of this guide, you will have a node ready to install Edera. Get your license Create an account at on.edera.dev if you don’t have one Log in and click Create License Click Show to reveal your license key Your license key is used during installation to authenticate to the Edera registry. ⚠️ One license key can only be active on one machine at a time. Deactivate your node from the dashboard before reusing a license on a different machine. System requirements RAM 4 GB minimum Disk 30 GB minimum Virtualization Hardware virt. enabled Boot mode UEFI required Container runtime Docker (or Podman on CentOS/RHEL) OS Ubuntu 24.04+, Amazon Linux 2023, CentOS Stream 9, RHEL 10 No UEFI required — any EC2 instance type with hardware virtualization works (t3, m5, m6i, and more). (1059 words) - [docs/reference/cri-toml/_index-md.html](/content/docs/reference/cri-toml/_index-md.html) (15 words) - [CLI v0.0.1 – Edera](/content/docs/reference/cli/v0-0-1.html): v0.0.1 CLI Version v1.10.0 (Latest) v1.6.0 v1.3.0 v0.0.1 ✓ ⚠️ The Edera Protect CLI is under active development. Options, Commands and Subcommands are subject to change. Using the CLI protect [OPTIONS] Option reference -c, --connection The connection URL to the Edera Protect daemon [default: unix:///var/lib/edera/protect/daemon.socket]. -h, --help Print help. -v, --version Print version. ℹ️ All commands and subcommands can be used with --help or -h for more information. Command reference zone Manage the zones., v0.0.1 CLI Version v1.10.0 (Latest) v1.6.0 v1.3.0 v0.0.1 ✓ ⚠️ The Edera Protect CLI is under active development. Options, Commands and Subcommands are subject to change. Using the CLI protect [OPTIONS] Option reference -c, --connection The connection URL to the Edera Protect daemon [default: unix:///var/lib/edera/protect/daemon.socket]. -h, --help Print help. -v, --version Print version. ℹ️ All commands and subcommands can be used with --help or -h for more information. Command reference zone Manage the zones. (338 words) - [daemon.toml – Edera](/content/docs/reference/configuration/daemon-toml/index.html): Reference for the daemon.toml configuration file used by the Edera Protect daemon., Reference for the daemon.toml configuration file used by the Edera Protect daemon. (1873 words) - [docs/concepts/ai-agent-isolation/index.html](/content/docs/concepts/ai-agent-isolation/index.html) (1,117 words) - [Falco security monitoring with Edera – Edera](/content/docs/guides/observability/falco-integration/index.html): Deploy Falco runtime security monitoring to detect threats and suspicious activity in Edera protected zones, Deploy Falco runtime security monitoring to detect threats and suspicious activity in Edera protected zones (3341 words) - [Speculative execution mitigations in Edera – Edera](/content/docs/technical-overview/speculative-execution-mitigations/index.html): How Edera Protect mitigates speculative execution vulnerabilities through hardware and software features, and when it makes sense to disable them, How Edera Protect mitigates speculative execution vulnerabilities through hardware and software features, and when it makes sense to disable them (1658 words) - [docs/guides/advanced/index.html](/content/docs/guides/advanced/index.html) (68 words) - [Metrics v1.8.4 – Edera](/content/docs/reference/observability/metrics/v1-8-4.html): v1.8.4 METRICS v1.10.0 (Latest) v1.8.4 ✓ v1.7.0 v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Collect metrics Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. These metrics are exposed by in the Prometheus format, by default on http://127.0.0.1:3035/. If an alternative address is preferred, it can be provided to the metrics-http-listen-addr flag on the protect-orchestrator service., v1.8.4 METRICS v1.10.0 (Latest) v1.8.4 ✓ v1.7.0 v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Collect metrics Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. These metrics are exposed by in the Prometheus format, by default on http://127.0.0.1:3035/. If an alternative address is preferred, it can be provided to the metrics-http-listen-addr flag on the protect-orchestrator service. (848 words) - [docs/concepts/hypervisor/index.html](/content/docs/concepts/hypervisor/index.html) (362 words) - [v1.5.0 – Edera](/content/docs/reference/release-notes/v1-5-0.html): v1.5.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 ✓ v1.4.0 v1.3.0 v1.2.0 Release Notes ✨ New Features & Enhancements Falco Plugin Published & Open-Sourced The Edera Falco plugin is now published as part of formal Edera releases and is fully open-sourced. The plugin now exposes the same queryable fields on zone-level events that Falco exposes for host events. Supported field classes include: evt evt (syscalls) process fd fs.path fdlist This enables first-class Falco rule support for zones without requiring kernel access or host-level privileges., v1.5.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 ✓ v1.4.0 v1.3.0 v1.2.0 Release Notes ✨ New Features & Enhancements Falco Plugin Published & Open-Sourced The Edera Falco plugin is now published as part of formal Edera releases and is fully open-sourced. The plugin now exposes the same queryable fields on zone-level events that Falco exposes for host events. Supported field classes include: evt evt (syscalls) process fd fs.path fdlist This enables first-class Falco rule support for zones without requiring kernel access or host-level privileges. (347 words) - [KVM architecture – Edera](/content/docs/technical-overview/architecture/kvm/index.html): TL;DR Edera zones run on Xen by default. The same zone-based isolation also runs on KVM—preserving identical security guarantees while meeting teams where their infrastructure already is. Why KVM KVM represents a deliberate infrastructure choice for many organizations, backed by years of tooling, expertise, and certification work. Requiring a hypervisor swap to adopt strong container isolation is a non-starter for most of these teams., TL;DR Edera zones run on Xen by default. The same zone-based isolation also runs on KVM—preserving identical security guarantees while meeting teams where their infrastructure already is. Why KVM KVM represents a deliberate infrastructure choice for many organizations, backed by years of tooling, expertise, and certification work. Requiring a hypervisor swap to adopt strong container isolation is a non-starter for most of these teams. (1098 words) - [Metrics v1.3.0 – Edera](/content/docs/reference/observability/metrics/v1-3-0.html): v1.3.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 v1.3.0 ✓ v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on., v1.3.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 v1.3.0 ✓ v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. (550 words) - [CPU management in Edera – Edera](/content/docs/technical-overview/cpu-management/index.html): How Edera allocates and schedules CPU resources using the Xen hypervisor and paravirtualized virtual machines., How Edera allocates and schedules CPU resources using the Xen hypervisor and paravirtualized virtual machines. (879 words) - [v1.10.0 – Edera](/content/docs/reference/release-notes/v1-10-0.html): v1.10.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 ✓ v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes These release notes describe all changes since the previous minor release, v1.9.0, not since the most recent 1.9.x patch. Some of the fixes and enhancements listed below were also delivered in the v1.9.1 patch release; they are repeated here so this page is a complete record of what changed between 1.9.0 and 1.10.0., v1.10.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 ✓ v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes These release notes describe all changes since the previous minor release, v1.9.0, not since the most recent 1.9.x patch. Some of the fixes and enhancements listed below were also delivered in the v1.9.1 patch release; they are repeated here so this page is a complete record of what changed between 1.9.0 and 1.10.0. (764 words) - [Metrics v1.7.0 – Edera](/content/docs/reference/observability/metrics/v1-7-0.html): v1.7.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 ✓ v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on., v1.7.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 ✓ v1.3.0 v1.2.0 ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. (550 words) - [docs/support/troubleshooting/utilities/support-edera-dev.html](/content/docs/support/troubleshooting/utilities/support-edera-dev.html) (15 words) - [Metrics v1.2.0 – Edera](/content/docs/reference/observability/metrics/v1-2-0.html): v1.2.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 v1.3.0 v1.2.0 ✓ ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on., v1.2.0 METRICS v1.10.0 (Latest) v1.8.4 v1.7.0 v1.3.0 v1.2.0 ✓ ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. (386 words) - [How Edera’s components fit together – Edera](/content/docs/technical-overview/architecture/components/index.html): How Edera’s components fit together: hypervisor, kernels, user-space daemons, IDM, and orchestration—with practical debugging entry points., How Edera’s components fit together: hypervisor, kernels, user-space daemons, IDM, and orchestration—with practical debugging entry points. (827 words) - [v1.6.0 – Edera](/content/docs/reference/release-notes/v1-6-0.html): v1.6.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 ✓ v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements Default host kernel is now 6.18.6 (LTS) Improves performance and device compatibility., v1.6.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 ✓ v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements Default host kernel is now 6.18.6 (LTS) Improves performance and device compatibility. (520 words) - [What is EderaON? – EderaON](/content/on/what-is-ederaon/index.html): A free, single-node tier of Edera for evaluating hardened container runtime protection on your own infrastructure. EderaON runs each container inside its own lightweight virtual machine, giving you hardware-level isolation that stops container escapes from reaching other workloads or the host. How isolation works Choose your isolation backend. The installer defaults to Xen. Xen Recommended Type-1 hypervisor. Provides maximum security and performance with isolation independent of the host OS kernel. Requires UEFI boot mode and compatible instance types. KVM Coming Soon Works on any Linux VM with hardware virtualization, no UEFI required. KVM support is not yet available — Xen is the current path for EderaON. What you get A one-node license valid for 90 days, the Edera runtime, access to Edera images via images.edera.dev, and community support via GitHub Issues., A free, single-node tier of Edera for evaluating hardened container runtime protection on your own infrastructure. EderaON runs each container inside its own lightweight virtual machine, giving you hardware-level isolation that stops container escapes from reaching other workloads or the host. How isolation works Choose your isolation backend. The installer defaults to Xen. Xen Recommended Type-1 hypervisor. Provides maximum security and performance with isolation independent of the host OS kernel. Requires UEFI boot mode and compatible instance types. KVM Coming Soon Works on any Linux VM with hardware virtualization, no UEFI required. KVM support is not yet available — Xen is the current path for EderaON. What you get A one-node license valid for 90 days, the Edera runtime, access to Edera images via images.edera.dev, and community support via GitHub Issues. (206 words) - [Operations integration suite – Edera](/content/docs/guides/validate/operations/index.html): Verify Edera integrates with existing observability tools and automation workflows., Verify Edera integrates with existing observability tools and automation workflows. (971 words) - [docs/concepts/vm-containers/index.html](/content/docs/concepts/vm-containers/index.html) (471 words) - [v1.9.0 – Edera](/content/docs/reference/release-notes/v1-9-0.html): v1.9.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 ✓ v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes These release notes describe all changes since the previous minor release, v1.8.0, not since the most recent 1.8.x patch. Some of the fixes and enhancements listed below were also delivered in the v1.8.1 through v1.8.8 patch releases; they are repeated here so this page is a complete record of what changed across the 1.8 line., v1.9.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 ✓ v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes These release notes describe all changes since the previous minor release, v1.8.0, not since the most recent 1.8.x patch. Some of the fixes and enhancements listed below were also delivered in the v1.8.1 through v1.8.8 patch releases; they are repeated here so this page is a complete record of what changed across the 1.8 line. (628 words) - [VM-image zones – Edera](/content/docs/technical-overview/concepts/vm-image-zones/index.html): TL;DR A VM-image zone boots an unmodified raw or qcow2 virtual machine disk image directly as an Edera zone, alongside Edera’s OCI-based zones. It runs on the KVM backend and keeps the same zone isolation guarantees—without requiring the image to be repackaged as a container. Why VM-image zones Edera zones are normally built from OCI images: Edera supplies the kernel and initrd and composes the root filesystem from container layers. That model doesn’t fit workloads distributed as whole virtual machines—GPU vendor fleet images, vendor-supplied appliances, or any system that expects to own its bootloader and kernel. Repackaging those into containers is often infeasible., TL;DR A VM-image zone boots an unmodified raw or qcow2 virtual machine disk image directly as an Edera zone, alongside Edera’s OCI-based zones. It runs on the KVM backend and keeps the same zone isolation guarantees—without requiring the image to be repackaged as a container. Why VM-image zones Edera zones are normally built from OCI images: Edera supplies the kernel and initrd and composes the root filesystem from container layers. That model doesn’t fit workloads distributed as whole virtual machines—GPU vendor fleet images, vendor-supplied appliances, or any system that expects to own its bootloader and kernel. Repackaging those into containers is often infeasible. (515 words) - [v1.7.0 – Edera](/content/docs/reference/release-notes/v1-7-0.html): v1.7.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 ✓ v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements PVH support Add support for allocation of 1 GB and 2 MB pages to improve performance., v1.7.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 ✓ v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements PVH support Add support for allocation of 1 GB and 2 MB pages to improve performance. (395 words) - [Edera system components – Edera](/content/docs/technical-overview/concepts/system-components/index.html): This page defines key binaries and resources used by Edera and its supporting services. While the CLI usage guide explains how to interact with the system via the command line, this reference focuses on what each binary or file does, where it lives on the system, and how it fits into the broader Edera runtime. Use this as a quick lookup when diagnosing issues or exploring system internals. Core binaries Name Type Purpose Location protect-network Long-lived Binary Provides networking to isolated zones via userspace bridges /usr/sbin protect-daemon Long-lived Binary Service which provides the control API to manage isolated zones /usr/sbin kube-spdy-proxy Long-lived Binary Translate legacy SPDY protocol in Kubernetes to modern HTTP/2.0 /usr/sbin protect-cri Long-lived Binary Provide the Container Runtime interface via the protect-daemon API /usr/sbin Command-line Name Type Purpose Location protect Command-line Binary Tool to connect to the control API, diagnose problems /usr/sbin Boot time & zone components Name Type Purpose Location xen Bootable Binary Provides the Edera Protect Xen hypervisor at boot time /boot kernel Zone Resource Default kernel image to boot inside of a zone /var/lib/edera/protect/zone addons.squashfs Zone Resource Default kernel addons (modules and driver bits) /var/lib/edera/protect/zone initrd Zone Resource Default initial ramdisk to boot inside of a zone /var/lib/edera/protect/zone Runtime Name Type Purpose Location host.uuid Runtime Resource Stores the UUID of the host (separate from hardware UUID) /var/lib/edera/protect protect.db Runtime Resource Stores critical zone management information /var/lib/edera/protect cri.v1.json Runtime Resource Stores information about the runtime of the CRI /var/lib/edera/protect cache Runtime Directory OCI and data cache files /var/lib/edera/protect KVM backend components (Early Access) These components are installed and invoked only on the KVM backend. On the Xen backend they are not present. See Install Edera for the install path and components reference for source pins and roles., This page defines key binaries and resources used by Edera and its supporting services. While the CLI usage guide explains how to interact with the system via the command line, this reference focuses on what each binary or file does, where it lives on the system, and how it fits into the broader Edera runtime. Use this as a quick lookup when diagnosing issues or exploring system internals. Core binaries Name Type Purpose Location protect-network Long-lived Binary Provides networking to isolated zones via userspace bridges /usr/sbin protect-daemon Long-lived Binary Service which provides the control API to manage isolated zones /usr/sbin kube-spdy-proxy Long-lived Binary Translate legacy SPDY protocol in Kubernetes to modern HTTP/2.0 /usr/sbin protect-cri Long-lived Binary Provide the Container Runtime interface via the protect-daemon API /usr/sbin Command-line Name Type Purpose Location protect Command-line Binary Tool to connect to the control API, diagnose problems /usr/sbin Boot time & zone components Name Type Purpose Location xen Bootable Binary Provides the Edera Protect Xen hypervisor at boot time /boot kernel Zone Resource Default kernel image to boot inside of a zone /var/lib/edera/protect/zone addons.squashfs Zone Resource Default kernel addons (modules and driver bits) /var/lib/edera/protect/zone initrd Zone Resource Default initial ramdisk to boot inside of a zone /var/lib/edera/protect/zone Runtime Name Type Purpose Location host.uuid Runtime Resource Stores the UUID of the host (separate from hardware UUID) /var/lib/edera/protect protect.db Runtime Resource Stores critical zone management information /var/lib/edera/protect cri.v1.json Runtime Resource Stores information about the runtime of the CRI /var/lib/edera/protect cache Runtime Directory OCI and data cache files /var/lib/edera/protect KVM backend components (Early Access) These components are installed and invoked only on the KVM backend. On the Xen backend they are not present. See Install Edera for the install path and components reference for source pins and roles. (386 words) - [NUMA topology with Edera – Edera](/content/docs/guides/memory-management/memory-numa/index.html): This guide provides an overview of how Edera manages CPU-Memory topology. As servers got larger and larger, maintaining fast connections to a server’s distant parts became more complicated. Modern machines simplify by using an interconnect like HyperTransport or Intel’s UltraPath Interconnect. These introduce the concepts of locality and non-uniform memory access: an individual CPU core might have very fast access to its own ’local’ memory. However, if it wants to talk to the totality of system memory, it may have to make a transaction across the interconnect. These transactions take orders of magnitude more time than a local request and your performance can suffer greatly if you are crossing the interconnect needlessly. Therefore the quest for memory performance becomes a challenge of ensuring that CPU cores stay close to the memory they’re operating on., This guide provides an overview of how Edera manages CPU-Memory topology. As servers got larger and larger, maintaining fast connections to a server’s distant parts became more complicated. Modern machines simplify by using an interconnect like HyperTransport or Intel’s UltraPath Interconnect. These introduce the concepts of locality and non-uniform memory access: an individual CPU core might have very fast access to its own ’local’ memory. However, if it wants to talk to the totality of system memory, it may have to make a transaction across the interconnect. These transactions take orders of magnitude more time than a local request and your performance can suffer greatly if you are crossing the interconnect needlessly. Therefore the quest for memory performance becomes a challenge of ensuring that CPU cores stay close to the memory they’re operating on. (1774 words) - [NVIDIA GPU Operator with Edera zones – Edera](/content/docs/guides/gpu/gpu-operator/index.html): Install the NVIDIA GPU Operator configured for Edera and run GPU workloads on Edera-backed pods in Kubernetes., Install the NVIDIA GPU Operator configured for Edera and run GPU workloads on Edera-backed pods in Kubernetes. (1696 words) - [v1.4.0 – Edera](/content/docs/reference/release-notes/v1-4-0.html): v1.4.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 ✓ v1.3.0 v1.2.0 Release overview This release delivers major new capabilities around hardware passthrough, memory management, and observability, while continuing to strengthen stability and compatibility across environments. Key highlights include PCI passthrough for PVH guests, SR-IOV and network device passthrough, dynamic memory ballooning for better scheduling, and syscall forwarding to integrate with Falco and other eBPF-based tooling., v1.4.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 ✓ v1.3.0 v1.2.0 Release overview This release delivers major new capabilities around hardware passthrough, memory management, and observability, while continuing to strengthen stability and compatibility across environments. Key highlights include PCI passthrough for PVH guests, SR-IOV and network device passthrough, dynamic memory ballooning for better scheduling, and syscall forwarding to integrate with Falco and other eBPF-based tooling. (377 words) - [Using the Protect CLI – Edera](/content/docs/guides/cli-user-guide/index.html): Learn how to use the protect CLI effectively, understand command outputs, and troubleshoot common issues, Learn how to use the protect CLI effectively, understand command outputs, and troubleshoot common issues (1681 words) - [v1.8.0 – Edera](/content/docs/reference/release-notes/v1-8-0.html): v1.8.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 ✓ v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements Improved OCI Handling Adopt the ocirender Rust library for OCI image handling for improved image compatibility, conformance, and performance., v1.8.0 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 ✓ v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements Improved OCI Handling Adopt the ocirender Rust library for OCI image handling for improved image compatibility, conformance, and performance. (429 words) - [Image management and OverlayFS – Edera](/content/docs/technical-overview/image-management/index.html): Edera manages container images through its own OCI-compliant pipeline rather than relying on third-party container OCI runtimes like containerd (Docker) or CRI-O. This page explains how images move from a registry into a running container filesystem inside an Edera zone. Why Edera manages images independently Each Edera zone runs inside its own virtual machine with a dedicated kernel. The zone boundary is a hard isolation line. Nothing from the host’s default container runtime crosses into the zone. This means the default container runtime image cache, snapshotter, and filesystem layers are not visible to the zone., Edera manages container images through its own OCI-compliant pipeline rather than relying on third-party container OCI runtimes like containerd (Docker) or CRI-O. This page explains how images move from a registry into a running container filesystem inside an Edera zone. Why Edera manages images independently Each Edera zone runs inside its own virtual machine with a dedicated kernel. The zone boundary is a hard isolation line. Nothing from the host’s default container runtime crosses into the zone. This means the default container runtime image cache, snapshotter, and filesystem layers are not visible to the zone. (714 words) - [v1.3.0 – Edera](/content/docs/reference/release-notes/v1-3-0.html): Kubernetes 1.33 support, PVH stability, faster pulls, and expanded observability., Kubernetes 1.33 support, PVH stability, faster pulls, and expanded observability. (390 words) - [v1.5.1 – Edera](/content/docs/reference/release-notes/v1-5-1.html): v1.5.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 ✓ v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes ✨ New Features & Enhancements Additional Kubernetes securityContext field support securityContext.readOnlyRootFilesystem is now properly supported on container specs, v1.5.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 ✓ v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes ✨ New Features & Enhancements Additional Kubernetes securityContext field support securityContext.readOnlyRootFilesystem is now properly supported on container specs (332 words) - [Verifying zone kernel images – Edera](/content/docs/guides/kernel/verifying-zone-kernels/index.html): How to verify the authenticity and integrity of Edera zone kernel OCI images using Sigstore cosign, How to verify the authenticity and integrity of Edera zone kernel OCI images using Sigstore cosign (871 words) - [v1.10.1 – Edera](/content/docs/reference/release-notes/v1-10-1.html): v1.10.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 ✓ v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.0 release notes for more information., v1.10.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 ✓ v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.0 release notes for more information. (202 words) - [Memory bandwidth benchmarking – Edera](/content/docs/guides/validate/memory-benchmarking/index.html): Validate memory bandwidth in Edera zones against standard containers using single-threaded and multi-threaded workloads., Validate memory bandwidth in Edera zones against standard containers using single-threaded and multi-threaded workloads. (812 words) - [CLI reference – Edera](/content/docs/reference/cli/index.html): Command-line interface documentation for Edera, Command-line interface documentation for Edera (228 words) - [FAQ – Edera](/content/docs/support/faq/index.html): I want to try Edera—how do I get access? Edera is now generally available. If you’re interested in access or becoming one of our design partners, please reach out via our contact form. What are the system requirements for running Edera? Edera is designed for flexibility and minimal host dependencies. Since we install a microkernel to manage containers in guest VMs, there are no userspace package requirements on the host., I want to try Edera—how do I get access? Edera is now generally available. If you’re interested in access or becoming one of our design partners, please reach out via our contact form. What are the system requirements for running Edera? Edera is designed for flexibility and minimal host dependencies. Since we install a microkernel to manage containers in guest VMs, there are no userspace package requirements on the host. (1143 words) - [Edera for Security Engineers – Edera](/content/docs/for/security/index.html): Documentation for security engineers and architects, Documentation for security engineers and architects (78 words) - [v1.7.2 – Edera](/content/docs/reference/release-notes/v1-7-2.html): v1.7.2 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 ✓ v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release., v1.7.2 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 ✓ v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. (112 words) - [v1.8.8 – Edera](/content/docs/reference/release-notes/v1-8-8.html): v1.8.8 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 ✓ v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.6 release notes for more information., v1.8.8 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 ✓ v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.6 release notes for more information. (154 words) - [General troubleshooting – Edera](/content/docs/support/troubleshooting/general/index.html): First step: run edera-check If something isn’t working, start by running edera-check postinstall on the affected node: sudo edera-check postinstall Or via Docker: docker run --pull always --pid host --privileged \ ghcr.io/edera-dev/edera-check:stable postinstall This validates your system configuration and generates a diagnostic report bundle (a .tar.gz file saved locally). If you need to contact support, send this bundle to support@edera.dev. It contains the system info we need to help diagnose your environment., First step: run edera-check If something isn’t working, start by running edera-check postinstall on the affected node: sudo edera-check postinstall Or via Docker: docker run --pull always --pid host --privileged \ ghcr.io/edera-dev/edera-check:stable postinstall This validates your system configuration and generates a diagnostic report bundle (a .tar.gz file saved locally). If you need to contact support, send this bundle to support@edera.dev. It contains the system info we need to help diagnose your environment. (649 words) - [v1.9.1 – Edera](/content/docs/reference/release-notes/v1-9-1.html): v1.9.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 ✓ v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.9 series. Refer to the v1.9.0 release notes for more information., v1.9.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 ✓ v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.9 series. Refer to the v1.9.0 release notes for more information. (189 words) - [v1.8.1 – Edera](/content/docs/reference/release-notes/v1-8-1.html): v1.8.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 ✓ v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.0 release notes for more information., v1.8.1 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 ✓ v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.0 release notes for more information. (94 words) - [Reference – Edera](/content/docs/reference/index.html): Authoritative, lookup-oriented docs for exact details—commands, config schemas, APIs, and other specifications. Use Reference when you already know what you’re looking for and need the precise answer—flags, fields, defaults, limits, exit codes, version notes. CLI Configuration & tools Observability Edera release notes Release stages , Authoritative, lookup-oriented docs for exact details—commands, config schemas, APIs, and other specifications. Use Reference when you already know what you’re looking for and need the precise answer—flags, fields, defaults, limits, exit codes, version notes. CLI Configuration & tools Observability Edera release notes Release stages (44 words) - [Edera zones – Edera](/content/docs/technical-overview/concepts/zone/index.html): Edera runs Kubernetes pods inside of zones, which provide a security boundary for sensitive workloads. Running pods in an Edera zone eliminates container escape, privilege escalation, and lateral movement attacks. You can think of a zone as a virtual machine guest environment where pods run with a dedicated zone kernel. The zone kernel is separate from the host kernel and is pulled as an OCI image and unpacked into the zone to run the workload. Edera Protect zones run a single pod by default, but can be configured to run a group of pods or a Kubernetes namespace., Edera runs Kubernetes pods inside of zones, which provide a security boundary for sensitive workloads. Running pods in an Edera zone eliminates container escape, privilege escalation, and lateral movement attacks. You can think of a zone as a virtual machine guest environment where pods run with a dedicated zone kernel. The zone kernel is separate from the host kernel and is pulled as an OCI image and unpacked into the zone to run the workload. Edera Protect zones run a single pod by default, but can be configured to run a group of pods or a Kubernetes namespace. (499 words) - [Edera for Platform Engineers – Edera](/content/docs/for/platform-engineers/index.html): Documentation for infrastructure and platform teams, Documentation for infrastructure and platform teams (106 words) - [v1.8.6 – Edera](/content/docs/reference/release-notes/v1-8-6.html): v1.8.6 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 ✓ v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.3 release notes for more information., v1.8.6 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 ✓ v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.3 release notes for more information. (134 words) - [Security reference architecture – Edera](/content/docs/technical-overview/security/reference-architecture/index.html): Prescriptive security architecture for deploying Edera in enterprise environments, Prescriptive security architecture for deploying Edera in enterprise environments (1673 words) - [v1.10.5 – Edera](/content/docs/reference/release-notes/v1-10-5.html): v1.10.5 RELEASE NOTES v1.10.11 (Latest) v1.10.5 ✓ v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.1 release notes for more information., v1.10.5 RELEASE NOTES v1.10.11 (Latest) v1.10.5 ✓ v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.1 release notes for more information. (125 words) - [What is paravirtualization? – Edera](/content/docs/technical-overview/concepts/paravirtualization/index.html): How Edera uses paravirtualization (specifically Xen PV) to deliver lightweight VMs with strong isolation and fast boot times., How Edera uses paravirtualization (specifically Xen PV) to deliver lightweight VMs with strong isolation and fast boot times. (583 words) - [v1.8.2 – Edera](/content/docs/reference/release-notes/v1-8-2.html): v1.8.2 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 ✓ v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.1 release notes for more information., v1.8.2 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 ✓ v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.1 release notes for more information. (125 words) - [v1.9.5 – Edera](/content/docs/reference/release-notes/v1-9-5.html): v1.9.5 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 ✓ v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.9 series. Refer to the v1.9.0 release notes for more information., v1.9.5 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 ✓ v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.9 series. Refer to the v1.9.0 release notes for more information. (102 words) - [CPU performance benchmarking – Edera](/content/docs/guides/validate/cpu-benchmarking/index.html): Validate CPU performance in Edera zones against standard containers using real-world, multi-threaded workloads., Validate CPU performance in Edera zones against standard containers using real-world, multi-threaded workloads. (864 words) - [v1.10.11 – Edera](/content/docs/reference/release-notes/v1-10-11.html): v1.10.11 (Latest) RELEASE NOTES v1.10.11 (Latest) ✓ v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.0 release notes for more information., v1.10.11 (Latest) RELEASE NOTES v1.10.11 (Latest) ✓ v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.10 series. Refer to the v1.10.0 release notes for more information. (92 words) - [v1.8.3 – Edera](/content/docs/reference/release-notes/v1-8-3.html): v1.8.3 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 ✓ v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.2 release notes for more information., v1.8.3 RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 ✓ v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 Release Notes New Features & Enhancements There are no new features or enhancements in this release. This is a point release in the 1.8 series. Refer to the v1.8.2 release notes for more information. (96 words) - [Install Edera – EderaON](/content/on/install-edera/index.html): The installer sets up the Edera runtime and configures your system. Your machine will reboot when it completes. 🚫 Disposable infrastructure only. Edera modifies your bootloader and there is no automated uninstall. Only install on instances or VMs you can terminate and recreate. Run the installer ℹ️ The installer defaults to Xen. KVM support is coming soon — Xen is the current path for EderaON. Option 1: ScriptOption 2: Manual EDERA_LICENSE_KEY= /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/edera-dev/learn/main/getting-started/edera-on-installer/scripts/install.sh)" Verify UEFI boot Xen requires UEFI. Run:, The installer sets up the Edera runtime and configures your system. Your machine will reboot when it completes. 🚫 Disposable infrastructure only. Edera modifies your bootloader and there is no automated uninstall. Only install on instances or VMs you can terminate and recreate. Run the installer ℹ️ The installer defaults to Xen. KVM support is coming soon — Xen is the current path for EderaON. Option 1: ScriptOption 2: Manual EDERA_LICENSE_KEY= /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/edera-dev/learn/main/getting-started/edera-on-installer/scripts/install.sh)" Verify UEFI boot Xen requires UEFI. Run: (409 words) - [Edera whitepaper – Edera](/content/docs/technical-overview/whitepaper/index.html): You can view or download the latest Edera whitepaper here: 📄 Download PDF, You can view or download the latest Edera whitepaper here: 📄 Download PDF (13 words) - [Installing Edera with AWS EKS – Edera](/content/docs/guides/install/eks/index.html): Quickstart guide to deploy Edera on AWS EKS using Terraform., Quickstart guide to deploy Edera on AWS EKS using Terraform. (1296 words) - [Install the DRA Driver for Edera Zones – Edera](/content/docs/guides/install/dra-driver/index.html): Install and operate the DRA Driver for Edera Zones—expose Zone capacity to the Kubernetes scheduler using Dynamic Resource Allocation., Install and operate the DRA Driver for Edera Zones—expose Zone capacity to the Kubernetes scheduler using Dynamic Resource Allocation. (1442 words) - [Updating your host kernel on Amazon Linux – Edera](/content/docs/guides/kernel/host-kernel-swap/index.html): This guide shows how to change and boot an Edera host kernel under Xen on Amazon Linux. Our AMIs are Amazon Linux (AL2023) with Edera baked in; use this when you want to pin or change the dom0 kernel directly from ghcr.io/edera-dev/host-kernel. The script handles images that export a kernel/ tree (not a root-layout tar), ensures the version string matches across /boot/vmlinuz-*, /boot/initramfs-*.img, and /lib/modules/*, creates a Xen GRUB entry, sets it as the default, and reboots., This guide shows how to change and boot an Edera host kernel under Xen on Amazon Linux. Our AMIs are Amazon Linux (AL2023) with Edera baked in; use this when you want to pin or change the dom0 kernel directly from ghcr.io/edera-dev/host-kernel. The script handles images that export a kernel/ tree (not a root-layout tar), ensures the version string matches across /boot/vmlinuz-*, /boot/initramfs-*.img, and /lib/modules/*, creates a Xen GRUB entry, sets it as the default, and reboots. (538 words) - [Observability and monitoring – Edera](/content/docs/guides/observability/index.html): Runtime security and observability for Edera protected zones, Runtime security and observability for Edera protected zones (29 words) - [Kubernetes networking with Edera – Edera](/content/docs/technical-overview/kubernetes-networking/index.html): Kubernetes networking with Edera For Edera-managed pods, Edera should seamlessly use your existing cluster CNI configuration to set up networking for Edera pods. The following CNIs have been tested with Edera: Cilium Both IPv4 and IPv6 mode supported. ⚠️ When using Cilium’s kube-proxy-replacement with Edera, the in-pod socket-level loadbalancer must be disabled for pods by configuring Cilium with socketLB.hostNamespaceOnly=true., Kubernetes networking with Edera For Edera-managed pods, Edera should seamlessly use your existing cluster CNI configuration to set up networking for Edera pods. The following CNIs have been tested with Edera: Cilium Both IPv4 and IPv6 mode supported. ⚠️ When using Cilium’s kube-proxy-replacement with Edera, the in-pod socket-level loadbalancer must be disabled for pods by configuring Cilium with socketLB.hostNamespaceOnly=true. (191 words) - [gVisor vs Edera: syscall interception vs virtualization – Edera](/content/docs/technical-overview/concepts/edera-vs-gvisor/index.html): How gVisor and Edera take fundamentally different approaches to container isolation and what that means architecturally., How gVisor and Edera take fundamentally different approaches to container isolation and what that means architecturally. (910 words) - [VM-per-container explained – Edera](/content/docs/technical-overview/concepts/vm-containers/index.html): Understand the differences between shared-kernel container runtimes like Docker and micro-VM-per-container models like Apple Container Framework and Edera Protect., Understand the differences between shared-kernel container runtimes like Docker and micro-VM-per-container models like Apple Container Framework and Edera Protect. (464 words) - [v1.2.0 – Edera](/content/docs/reference/release-notes/v1-2-0.html): Important fixes, host block device support, and new metrics., Important fixes, host block device support, and new metrics. (305 words) - [edera-check – Edera](/content/docs/reference/configuration/edera-check/index.html): CLI tool to validate system readiness before and after installing Edera., CLI tool to validate system readiness before and after installing Edera. (623 words) - [Building your own Edera host kernel – Edera](/content/docs/guides/kernel/byo-host-kernel/index.html): Advanced guide to customize, verify, or build Linux kernel OCI images for use in Edera hosts, Advanced guide to customize, verify, or build Linux kernel OCI images for use in Edera hosts (464 words) - [Concepts – Edera](/content/docs/technical-overview/concepts/index.html): What makes Edera tick? Hypervisors, runtime behavior, security model. Edera Zones Edera system components What is a hypervisor and how does Edera fit in? What is paravirtualization and how does Edera use it? Rethinking container isolation: VM-per-container explained VM-image zones: boot raw and qcow2 disk images directly AI agent sandboxing: why isolation is required, not optional Image management and OverlayFS Kata Containers vs Edera gVisor vs Edera , What makes Edera tick? Hypervisors, runtime behavior, security model. Edera Zones Edera system components What is a hypervisor and how does Edera fit in? What is paravirtualization and how does Edera use it? Rethinking container isolation: VM-per-container explained VM-image zones: boot raw and qcow2 disk images directly AI agent sandboxing: why isolation is required, not optional Image management and OverlayFS Kata Containers vs Edera gVisor vs Edera (67 words) - [AMD GPU passthrough to an Edera zone – Edera](/content/docs/guides/gpu/amd-passthrough/index.html): Guide to passthrough a GPU to an Edera zone and run AI workloads, Guide to passthrough a GPU to an Edera zone and run AI workloads (880 words) - [Manually disable Edera Kubernetes integration – Edera](/content/docs/support/troubleshooting/disable/index.html): This guide explains how to manually disable the Edera Kubernetes integration on a node. ⚠️ This is an emergency procedure—not a supported uninstall—and should only be used if the Edera container runtime proxy is interfering with normal Kubernetes operations. Please follow the general troubleshooting steps first or contact Edera support, This guide explains how to manually disable the Edera Kubernetes integration on a node. ⚠️ This is an emergency procedure—not a supported uninstall—and should only be used if the Edera container runtime proxy is interfering with normal Kubernetes operations. Please follow the general troubleshooting steps first or contact Edera support (467 words) - [AWS troubleshooting – Edera](/content/docs/support/troubleshooting/aws/index.html): ℹ️ If you need the account id for our AMI please contact support@edera.dev AWS debugging utilities Get EKS node AMI & Edera version edera_aws_node_version() { NODES=( $(kubectl get nodes --no-headers | awk '{print $1}') ) echo "Fetching AWS image data..." IMAGE_DATA=$(aws ec2 describe-images --owners --query 'Images | sort_by(@, &CreationDate) | reverse(@) | [*].[ImageId, Name, State, CreationDate]' --output table) for NODE in "${NODES[@]}"; do NODE_AMI=$(kubectl get node "$NODE" -o json | jq -r '.metadata.labels["eks.amazonaws.com/nodegroup-image"]') EDERA_PROTECT_VERSION=$(echo "$IMAGE_DATA" | grep "$NODE_AMI" | awk '{print $3}') echo "Node: $NODE | AMI: $NODE_AMI | Edera: $EDERA_PROTECT_VERSION" done } List AMIs aws ec2 describe-images --filters Name=name,Values="*edera*" --query 'Images[*].[ImageId,Name,CreationDate]' --output table SSH reconnection after reboot The Edera installer reboots the instance into a new kernel. AWS instances typically take 1-3 minutes to come back up, but it can take longer depending on instance type and initramfs generation time., ℹ️ If you need the account id for our AMI please contact support@edera.dev AWS debugging utilities Get EKS node AMI & Edera version edera_aws_node_version() { NODES=( $(kubectl get nodes --no-headers | awk '{print $1}') ) echo "Fetching AWS image data..." IMAGE_DATA=$(aws ec2 describe-images --owners --query 'Images | sort_by(@, &CreationDate) | reverse(@) | [*].[ImageId, Name, State, CreationDate]' --output table) for NODE in "${NODES[@]}"; do NODE_AMI=$(kubectl get node "$NODE" -o json | jq -r '.metadata.labels["eks.amazonaws.com/nodegroup-image"]') EDERA_PROTECT_VERSION=$(echo "$IMAGE_DATA" | grep "$NODE_AMI" | awk '{print $3}') echo "Node: $NODE | AMI: $NODE_AMI | Edera: $EDERA_PROTECT_VERSION" done } List AMIs aws ec2 describe-images --filters Name=name,Values="*edera*" --query 'Images[*].[ImageId,Name,CreationDate]' --output table SSH reconnection after reboot The Edera installer reboots the instance into a new kernel. AWS instances typically take 1-3 minutes to come back up, but it can take longer depending on instance type and initramfs generation time. (345 words) - [Troubleshooting – Edera](/content/docs/support/troubleshooting/index.html): Tips and diagnostics for common issues when running Edera., Tips and diagnostics for common issues when running Edera. (30 words) - [Selecting a zone kernel variant – Edera](/content/docs/guides/kernel/kernel-variants/index.html): Select an alternate zone kernel by using kernel variants, Select an alternate zone kernel by using kernel variants (492 words) - [Performance – Edera](/content/docs/guides/performance/index.html): Guides for tuning zone performance with Edera, Guides for tuning zone performance with Edera (20 words) - [Escalate to Edera support – Edera](/content/docs/support/troubleshooting/escalate/index.html): How to collect diagnostic information and escalate to Edera support, How to collect diagnostic information and escalate to Edera support (424 words) - [Helpful utilities – Edera](/content/docs/support/troubleshooting/utilities/index.html): Handy scripts and shell snippets to make your life easier when working with Edera. Nothing fancy—just stuff that works. Apply the Edera RuntimeClass kubectl apply -f https://public.edera.dev/kubernetes/runtime-class.yaml Note: The Edera RuntimeClass requires nodes to be labeled with runtime=edera. See the installation guides for labeling instructions., Handy scripts and shell snippets to make your life easier when working with Edera. Nothing fancy—just stuff that works. Apply the Edera RuntimeClass kubectl apply -f https://public.edera.dev/kubernetes/runtime-class.yaml Note: The Edera RuntimeClass requires nodes to be labeled with runtime=edera. See the installation guides for labeling instructions. (283 words) - [Storage – Edera](/content/docs/guides/storage/index.html): Guides for using storage with Edera, Guides for using storage with Edera (24 words) - [Security demonstration suite – Edera](/content/docs/guides/validate/security/index.html): Validate Edera's container isolation and escape prevention capabilities through hands-on security tests., Validate Edera's container isolation and escape prevention capabilities through hands-on security tests. (738 words) - [Edera release notes – Edera](/content/docs/reference/release-notes/index.html): Here’s what’s new. Features, fixes, and everything else we’ve shipped to make Edera better. Pick a version to see what’s changed: RELEASE NOTES RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 , Here’s what’s new. Features, fixes, and everything else we’ve shipped to make Edera better. Pick a version to see what’s changed: RELEASE NOTES RELEASE NOTES v1.10.11 (Latest) v1.10.5 v1.10.1 v1.10.0 v1.9.5 v1.9.1 v1.9.0 v1.8.8 v1.8.6 v1.8.3 v1.8.2 v1.8.1 v1.8.0 v1.7.2 v1.7.0 v1.6.0 v1.5.1 v1.5.0 v1.4.0 v1.3.0 v1.2.0 (47 words) - [docs/guides/gpu/index.html](/content/docs/guides/gpu/index.html) (32 words) - [Kubernetes nodes/proxy RCE: When Monitoring Becomes an Attack Vector](/content/stories/your-monitoring-stack-just-became-a-rce-vector-a-deep-dive-into-the-kubernetes-nodes-proxy-rce.html): A deep dive into the Kubernetes nodes/proxy RCE flaw, why monitoring tools are affected, and how architectural isolation contains the blast radius. (2,579 words) - [Get support – Edera](/content/docs/support/index.html): Get the help you need with Edera. Whether you’re looking for answers to common questions, troubleshooting guidance, or want to contact our support team directly, we’re here to help. FAQ Troubleshooting Contact us , Get the help you need with Edera. Whether you’re looking for answers to common questions, troubleshooting guidance, or want to contact our support team directly, we’re here to help. FAQ Troubleshooting Contact us (33 words) - [Metrics – Edera](/content/docs/reference/observability/metrics/index.html): ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on., ℹ️ Edera metrics are currently in Alpha. New metrics are expected to be added, and existing metrics are subject to change. Edera exposes a set of metrics to provide an overview of the health and performance of Edera and the infrastructure it runs on. (133 words) - [GPU – Edera](/content/docs/guides/gpu/index-2.html): NVIDIA GPU passthrough to an Edera zone AMD GPU passthrough to an Edera zone NVIDIA GPU Operator with Edera zones , NVIDIA GPU passthrough to an Edera zone AMD GPU passthrough to an Edera zone NVIDIA GPU Operator with Edera zones (20 words) - [CVE-2026-33579: The OpenClaw /pair approve Vulnerability](/content/stories/the-openclaw-pair-approve-vulnerability-explained/index.html): CVE-2026-33579 lets any OpenClaw user run /pair approve and take full admin control. Here's what it is, why it's critical, and how isolation limits the damage. (1,809 words) - [Installing Edera on Linode – Edera](/content/docs/guides/install/linode/index.html): Quickstart guide to install Edera on Linode., Quickstart guide to install Edera on Linode. (38 words) - [Release stages – Edera](/content/docs/reference/release-stages/index.html): How Edera defines Early Access and General Availability, and what each stage means for support and stability., How Edera defines Early Access and General Availability, and what each stage means for support and stability. (136 words) - [Contact us – Edera](/content/docs/support/contact-us/index.html): Need access to Edera? Talk to the team to get started. Already a customer with a support issue? Reach out to support@edera.dev., Need access to Edera? Talk to the team to get started. Already a customer with a support issue? Reach out to support@edera.dev. (22 words) - [cri.toml – Edera](/content/docs/reference/configuration/cri-toml/index.html): Reference for the cri.toml configuration file used by Edera., Reference for the cri.toml configuration file used by Edera. (113 words) - [Using storage in Kubernetes – Edera](/content/docs/guides/storage/kubernetes-block-devices/index.html): Configure persistent storage for Edera workloads using Kubernetes PersistentVolume APIs, Configure persistent storage for Edera workloads using Kubernetes PersistentVolume APIs (1008 words) - [GPU support in Edera – Edera](/content/docs/technical-overview/gpu-support/index.html): How do GPUs work with Edera? Edera provides GPUs inside a zone with driver isolation, allowing the GPU driver to run outside of the host OS. GPUs in Edera can come from any vendor and follow standard GPU workflows. Support also extends to TPUs and DPU-style devices. Edera supports multiple GPU access methods, each with different requirements and tradeoffs: GPU Partitioning This is the most secure method for multi-tenant use cases. It creates subsections of GPU resources using supported hardware features (often referred to as Multi-instance GPUs) and passes them to the individual zones that need them., How do GPUs work with Edera? Edera provides GPUs inside a zone with driver isolation, allowing the GPU driver to run outside of the host OS. GPUs in Edera can come from any vendor and follow standard GPU workflows. Support also extends to TPUs and DPU-style devices. Edera supports multiple GPU access methods, each with different requirements and tradeoffs: GPU Partitioning This is the most secure method for multi-tenant use cases. It creates subsections of GPU resources using supported hardware features (often referred to as Multi-instance GPUs) and passes them to the individual zones that need them. (352 words) - [Security – Edera](/content/docs/guides/security/index.html): Guides for hardening and securing Edera deployments, Guides for hardening and securing Edera deployments (17 words) - [ocirender: Streaming OCI Layer Merge for Rust Infrastructure](/content/stories/rendering-oci-images-the-right-way-introducing-ocirender.html): ocirender is Edera's open source Rust library for correct, streaming OCI image assembly that solves hard link, whiteout, and PAX header edge cases. (3,719 words) - [Performance validation suite – Edera](/content/docs/guides/validate/performance/index.html): Benchmark network and CPU performance to validate Edera delivers container-like performance with VM-level security., Benchmark network and CPU performance to validate Edera delivers container-like performance with VM-level security. (728 words) - [Standalone (no Kubernetes) – Edera](/content/docs/guides/standalone/index.html): Guides for running Edera without Kubernetes using the protect CLI., Guides for running Edera without Kubernetes using the protect CLI. (30 words) - [docs/guides/pov-validation/index.html](/content/docs/guides/pov-validation/index.html) (17 words) - [Kernel customization – Edera](/content/docs/guides/kernel/index.html): Guides for customizing, building, and managing Edera host and zone kernels., Guides for customizing, building, and managing Edera host and zone kernels. (55 words) - [Memory ballooning – Edera](/content/docs/technical-overview/memory-ballooning/index.html): Overview Memory ballooning is a dynamic memory management technique that enables the Edera hypervisor to adjust the memory allocated to zones in real time. This allows the Edera platform to reallocate memory resources based on current usage patterns without requiring pod disruption. Why memory ballooning In virtualized environments, physical memory is a shared resource. When multiple Edera zones are deployed on a single node, the aggregate memory demand may exceed the node’s available capacity. Memory ballooning helps mitigate this issue by allowing the hypervisor to reclaim unused memory from some zones and redistribute it to other zones that require more memory based on usage patterns or a scaling event., Overview Memory ballooning is a dynamic memory management technique that enables the Edera hypervisor to adjust the memory allocated to zones in real time. This allows the Edera platform to reallocate memory resources based on current usage patterns without requiring pod disruption. Why memory ballooning In virtualized environments, physical memory is a shared resource. When multiple Edera zones are deployed on a single node, the aggregate memory demand may exceed the node’s available capacity. Memory ballooning helps mitigate this issue by allowing the hypervisor to reclaim unused memory from some zones and redistribute it to other zones that require more memory based on usage patterns or a scaling event. (287 words) - [eBPF – Edera](/content/docs/guides/ebpf/index.html): Using eBPF with Edera , Using eBPF with Edera (4 words) - [Fixing SandboxChanged Errors in Kubernetes Runtimes](/content/stories/sandboxchanged-errors-when-systemd-and-container-runtimes-fight-over-kubernetes-pods.html): SandboxChanged errors in Kubernetes often stem from cgroup misconfigurations. Learn how to debug and resolve these elusive pod restart issues. (2,082 words) - [docs/guides/pov-validation/memory-benchmarking/index.html](/content/docs/guides/pov-validation/memory-benchmarking/index.html) (17 words) - [How Edera uses OCI images – Edera](/content/docs/technical-overview/oci-images/index.html): How is OCI used throughout Edera? Edera is built on the philosophy that infrastructure should be composed the same way you compose your workloads. The Open Container Initiative (OCI) defines industry standards for container image formats and runtimes, enabling consistent packaging and execution across tools and platforms. That infrastructure should be composed in the same way you compose your workloads. To that end, Edera is distributed via OCI images, and each zone consumes OCI images as its inputs for the Linux kernel, driver zones, and system extensions. Zones can then run dynamic sets of OCI containers—known as workloads., How is OCI used throughout Edera? Edera is built on the philosophy that infrastructure should be composed the same way you compose your workloads. The Open Container Initiative (OCI) defines industry standards for container image formats and runtimes, enabling consistent packaging and execution across tools and platforms. That infrastructure should be composed in the same way you compose your workloads. To that end, Edera is distributed via OCI images, and each zone consumes OCI images as its inputs for the Linux kernel, driver zones, and system extensions. Zones can then run dynamic sets of OCI containers—known as workloads. (198 words) - [Kubernetes Pod Memory Metrics: Dedicated vs Shared Kernel](/content/stories/your-pods-kernel-has-better-metrics-than-your-monitoring-stack.html): We compared per-pod kernel metrics from dedicated kernels against cgroup metrics on shared kernels. The signal gap is significant. (2,666 words) - [Mixed deployment patterns – Edera](/content/docs/guides/deployment/mixed-deployment-patterns/index.html): Deployment strategies for running Edera alongside non-Edera workloads in production environments., Deployment strategies for running Edera alongside non-Edera workloads in production environments. (913 words) - [Autoscale with Edera zone metrics – Edera](/content/docs/guides/deployment/hpa/index.html): Wire Edera's per-pod zone metrics into a Horizontal Pod Autoscaler (HPA) using Prometheus and Prometheus Adapter, Wire Edera's per-pod zone metrics into a Horizontal Pod Autoscaler (HPA) using Prometheus and Prometheus Adapter (524 words) - [Install Edera – Edera](/content/docs/guides/install/edera-installer/index.html): How to install Edera on any supported Linux host using either the Xen or KVM hypervisor backend., How to install Edera on any supported Linux host using either the Xen or KVM hypervisor backend. (858 words) - [Configuration & tools – Edera](/content/docs/reference/configuration/index.html): Reference for Edera configuration files and system validation tools., Reference for Edera configuration files and system validation tools. (3 words) - [Observability – Edera](/content/docs/reference/observability/index.html): Metrics alpha , Metrics alpha (2 words) - [Memory ballooning with Edera – Edera](/content/docs/guides/memory-management/memory-ballooning/index.html): This guide provides an overview of how Edera manages memory ballooning, including its default settings, dynamic and static memory allocation modes, and manual adjustment options using the protect CLI. Whether you’re deploying Kubernetes workloads or specialized environments, this guide will help you optimize memory usage effectively. Default memory settings: Learn about Edera’s default max and target memory values and how to override them. Dynamic mode: Understand how memory is automatically adjusted based on usage. Static mode: Explore fixed memory allocation for advanced use cases. Manual adjustments: Use the protect CLI to fine-tune memory settings. Pod annotations: Simplify memory configuration directly in your Kubernetes manifests. For a deeper dive into memory ballooning and advanced configurations, refer to our technical guide on memory ballooning., This guide provides an overview of how Edera manages memory ballooning, including its default settings, dynamic and static memory allocation modes, and manual adjustment options using the protect CLI. Whether you’re deploying Kubernetes workloads or specialized environments, this guide will help you optimize memory usage effectively. Default memory settings: Learn about Edera’s default max and target memory values and how to override them. Dynamic mode: Understand how memory is automatically adjusted based on usage. Static mode: Explore fixed memory allocation for advanced use cases. Manual adjustments: Use the protect CLI to fine-tune memory settings. Pod annotations: Simplify memory configuration directly in your Kubernetes manifests. For a deeper dive into memory ballooning and advanced configurations, refer to our technical guide on memory ballooning. (767 words) - [How Workload Identity Strengthens Sovereign AI](/content/stories/sovereign-ai-how-workload-identity-solves-data-sovereignty-challenges.html): As AI & cloud computing reshape global industries, organizations face unprecedented data sovereignty challenges that traditional approaches simply cannot solve (674 words) - [Security – Edera](/content/docs/technical-overview/security/index.html): Security model, architecture, and hardening guidance for Edera deployments. Zone security model Security reference architecture , Security model, architecture, and hardening guidance for Edera deployments. Zone security model Security reference architecture (15 words) - [Injecting the Edera RuntimeClass with Kyverno – Edera](/content/docs/guides/deployment/kyverno/index.html): Automatically apply the Edera RuntimeClass to Pods and controllers using Kyverno policies., Automatically apply the Edera RuntimeClass to Pods and controllers using Kyverno policies. (469 words) - [Using a scratch disk with Edera – Edera](/content/docs/guides/storage/scratch-disks/index.html): How to configure and use a scratch disk with Edera for high‑performance workloads, How to configure and use a scratch disk with Edera for high‑performance workloads (576 words) - [Choose a zone virtualization backend (PV or PVH) – Edera](/content/docs/guides/deployment/virtualization-backend/index.html): How to select PV or PVH for an Edera zone with the dev.edera/virt-backend annotation, and how to verify which backend a zone actually booted with., How to select PV or PVH for an Edera zone with the dev.edera/virt-backend annotation, and how to verify which backend a zone actually booted with. (704 words) - [Optimize zone performance – Edera](/content/docs/guides/performance/optimize-zone-performance/index.html): Configure zone resources and virtualization settings to maximize performance for your workloads., Configure zone resources and virtualization settings to maximize performance for your workloads. (429 words) - [Customize kernel parameters during install – Edera](/content/docs/guides/kernel/customize-kernel-parameters/index.html): Customize Xen and Linux kernel boot parameters when installing Edera., Customize Xen and Linux kernel boot parameters when installing Edera. (340 words) - [RediShell Shows Why Isolation Isn’t Optional](/content/stories/why-container-isolation-isnt-optional-lessons-from-redishell.html): RediShell exposes the fatal flaw in container security: shared kernels. Learn how Edera’s hardware-enforced isolation stops container escapes for good. (1,292 words) - [NUMA-Aware Zone Placement in Edera Explained](/content/stories/numa-part-2-numa-aware-zone-placement-how-edera-decides.html): Edera zones auto-place on NUMA nodes at boot for consistent performance—no manual pinning. See how the placement algorithm works. (3,418 words) - [Technical overviews – Edera](/content/docs/technical-overview/index.html): The Technical Overview explains how Edera works. It’s for engineers and architects who want system context before implementing or operating the platform. Edera architecture overview Edera concepts Security Edera whitepaper Image management and OverlayFS Memory ballooning GPU Support in Edera CPU management in Edera How is OCI used throughout Edera Speculative execution mitigations in Edera DRA Driver for Edera Zones , The Technical Overview explains how Edera works. It’s for engineers and architects who want system context before implementing or operating the platform. Edera architecture overview Edera concepts Security Edera whitepaper Image management and OverlayFS Memory ballooning GPU Support in Edera CPU management in Edera How is OCI used throughout Edera Speculative execution mitigations in Edera DRA Driver for Edera Zones (60 words) - [Deployment – Edera](/content/docs/guides/deployment/index.html): Guides for deploying applications with Edera and managing mixed environments., Guides for deploying applications with Edera and managing mixed environments. (37 words) - [Kata Containers vs Edera – Edera](/content/docs/technical-overview/concepts/edera-vs-kata/index.html): Both run containers in VMs. The differences are architectural choices and deployment requirements., Both run containers in VMs. The differences are architectural choices and deployment requirements. (1199 words) - [Edera install guides – Edera](/content/docs/guides/install/index.html): Running the Edera installer Installing Edera with AWS EKS Installing Edera on Google Compute Engine (GCE) Installing Edera with Azure Linux Installing Edera on Linode Install the DRA Driver for Edera Zones Install Edera with KVM early access , Running the Edera installer Installing Edera with AWS EKS Installing Edera on Google Compute Engine (GCE) Installing Edera with Azure Linux Installing Edera on Linode Install the DRA Driver for Edera Zones Install Edera with KVM early access (38 words) - [docs/guides/pov-validation/cpu-benchmarking/index.html](/content/docs/guides/pov-validation/cpu-benchmarking/index.html) (15 words) - [CVE-2025-62518 Shows the Cost of Open Source Abandonware](/content/stories/tarmageddon/index.html): Edera uncovers TARmageddon (CVE-2025-62518), a Rust async-tar RCE flaw exposing the real dangers of open-source abandonware and supply chain security. (1,428 words) - [Deploy your app to Edera – Edera](/content/docs/guides/deployment/deploy-apps/index.html): How to run your existing containers with Edera's hypervisor isolation, How to run your existing containers with Edera's hypervisor isolation (297 words) - [Installing Edera on Google Compute Engine (GCE) – Edera](/content/docs/guides/install/gce/index.html): How to install Edera on Google Compute Engine and integrate with self-managed Kubernetes clusters., How to install Edera on Google Compute Engine and integrate with self-managed Kubernetes clusters. (287 words) - [Overview – Edera](/content/docs/overview/index.html): Edera is a secure-by-default, cloud-native platform built on a reimagined memory-safe type-1 hypervisor that provides container isolation without performance tradeoffs., Edera is a secure-by-default, cloud-native platform built on a reimagined memory-safe type-1 hypervisor that provides container isolation without performance tradeoffs. (307 words) - [What is a hypervisor? – Edera](/content/docs/technical-overview/concepts/hypervisor/index.html): TL;DR Containers were never built for security. Hypervisors were. Edera gives you the best of both—without the overhead or complexity. So what is a hypervisor? Imagine your computer is a big apartment building. Traditional containers are like roommates—sharing the same kitchen, bathroom, and front door (a.k.a. the Linux kernel). They live together, share everything, and hope no one misbehaves. But sometimes you want privacy. Or you don’t trust your roommates. Or maybe you’re trying to work from home and don’t want someone else’s video streaming slowing down your bandwidth., TL;DR Containers were never built for security. Hypervisors were. Edera gives you the best of both—without the overhead or complexity. So what is a hypervisor? Imagine your computer is a big apartment building. Traditional containers are like roommates—sharing the same kitchen, bathroom, and front door (a.k.a. the Linux kernel). They live together, share everything, and hope no one misbehaves. But sometimes you want privacy. Or you don’t trust your roommates. Or maybe you’re trying to work from home and don’t want someone else’s video streaming slowing down your bandwidth. (358 words) - [Guides – Edera](/content/docs/guides/index.html): Step-by-step, task‑oriented instructions for installing, configuring, and operating Edera. Start here when you want to accomplish something specific—each guide lists prerequisites, commands, and expected outcomes If you’re looking for background and design rationale, see Technical Overviews. For CLI/API details, schemas, and exact flags, see Reference. For first‑time setup, see Getting Started. Install Edera GPU Deployment Memory management eBPF Kernel customization Standalone (no Kubernetes) Storage Resource utilization Performance Validation guide Observability and monitoring Security Using the Protect CLI , Step-by-step, task‑oriented instructions for installing, configuring, and operating Edera. Start here when you want to accomplish something specific—each guide lists prerequisites, commands, and expected outcomes If you’re looking for background and design rationale, see Technical Overviews. For CLI/API details, schemas, and exact flags, see Reference. For first‑time setup, see Getting Started. Install Edera GPU Deployment Memory management eBPF Kernel customization Standalone (no Kubernetes) Storage Resource utilization Performance Validation guide Observability and monitoring Security Using the Protect CLI (77 words) - [DRA Driver for Edera Zones – Edera](/content/docs/technical-overview/dra-driver/index.html): How Edera exposes per-node Zone capacity to the Kubernetes scheduler using Dynamic Resource Allocation (DRA)., How Edera exposes per-node Zone capacity to the Kubernetes scheduler using Dynamic Resource Allocation (DRA). (1164 words) - [Edera architecture overview – Edera](/content/docs/technical-overview/architecture/overview/index.html): TL;DR Edera provides hardened container isolation by running each workload inside its own lightweight virtual machine called a zone. Zones are powered by a hypervisor based on Xen (with most components rebuilt in Rust) and packaged as OCI images for fast boot and flexible composition. This architecture gives every workload its own Linux kernel, eliminates shared-kernel risks, and provides strong isolation without sacrificing cloud-native performance., TL;DR Edera provides hardened container isolation by running each workload inside its own lightweight virtual machine called a zone. Zones are powered by a hypervisor based on Xen (with most components rebuilt in Rust) and packaged as OCI images for fast boot and flexible composition. This architecture gives every workload its own Linux kernel, eliminates shared-kernel risks, and provides strong isolation without sacrificing cloud-native performance. (725 words) - [Software License Agreement | Edera](/content/software-license-agreement/index.html): Read the Edera Software License Agreement outlining usage terms, permissions, and responsibilities for secure deployment of Edera technology. (4,947 words) - [Memory management – Edera](/content/docs/guides/memory-management/index.html): Memory ballooning NUMA topology , Memory ballooning NUMA topology (4 words) - [Why Hardened Containers Aren’t Enough for Runtime Security](/content/stories/runtime-security-beyond-hardened-containers/index.html): Hardened images reduce CVEs, but runtime exploits thrive. Learn why hardened runtimes close the container security gap and stop lateral movement. (1,236 words) - [Xen Grant Tables and dom0 NUMA Blind Spot Explained](/content/stories/numa-part-3-xens-pv-i-o-path-and-its-numa-blind-spot.html): Xen's PV I/O drivers leave dom0 NUMA-blind: grant tables map guest RAM with no node info, costing every zone cross-socket latency. (3,655 words) - [Claiming devices with Edera – Edera](/content/docs/guides/storage/claiming-devices/index.html): How to claim and use block or PCI devices with Edera zones, How to claim and use block or PCI devices with Edera zones (523 words) - [AI Agents on Laptops: A Software Supply Chain Risk](/content/stories/your-laptop-is-not-a-build-system/index.html): AI agents on developer laptops inherit SSH keys, cloud credentials, and unchecked state. Here is why SLSA principles demand moving them to isolated infrastructu (1,855 words) - [Edera for Developers – Edera](/content/docs/for/developers/index.html): Documentation for application developers building with Edera, Documentation for application developers building with Edera (118 words) - [Real Kubernetes Isolation: Beyond Namespaces](/content/stories/beyond-namespaces-real-isolation-for-kubernetes-security.html): Namespaces partition, but they don’t isolate. Learn why real workload isolation, not logical separation, is key to Kubernetes security and resilience. (1,385 words) - [Installing Edera on Azure Linux – Edera](/content/docs/guides/install/azure-linux/index.html): Quickstart guide to install Edera on Azure Linux., Quickstart guide to install Edera on Azure Linux. (39 words) - [Why Edera Chose Xen for Secure Container Isolation](/content/stories/why-edera-built-on-xen-a-secure-container-foundation.html): Why Edera chose Xen: Type-1 security, paravirtualization for cloud, and a minimal attack surface redefine container infrastructure. (1,703 words) - [Linux User Namespaces: 262% More Kernel Attack Surface](/content/stories/user-namespaces-are-not-a-security-boundary/index.html): User namespaces expose 262% more kernel attack surface and enabled 40+ CVEs in 5 years. Here's what the data says—and what to do instead. (2,366 words) - [Building your own Edera zone kernel – Edera](/content/docs/guides/kernel/byo-zone-kernel/index.html): Advanced guide to customize, verify, or build Linux kernel OCI images for use in Edera zones, Advanced guide to customize, verify, or build Linux kernel OCI images for use in Edera zones (531 words) - [Open Source Summit + Embedded Linux Conference North America | Edera](/content/run/open-source-summit-na/index.html): Get to know Edera's OSS work at Open Source Summit + Embedded Linux Conference. (563 words) - [Raves and Love | Edera](/content/love/index.html): Check out what all the coolest folks on the internet think about Edera, our team, and our solutions that make secure computing simple. (675 words) - [James Petersen | Edera](/content/authors/james-petersen/index.html): James Petersen has a background in supply chain security, DevSecOps, and container runtimes across Chainguard, Anchore, and the US Government. He writes on Kubernetes internals, Rust, and low-level container behavior. (74 words) - [docs/concepts/paravirtualization/index.html](/content/docs/concepts/paravirtualization/index.html) (571 words) - [What Gardening Teaches Us About Open Source Work](/content/stories/spring-cleaning-what-community-gardening-has-taught-me-about-open-source-maintainership.html): Community gardening and open source maintainership: a group of people coming together to build something they are passionate about (537 words) - [Why Prevention Beats Detection-Only Security](/content/stories/the-end-of-detection-based-security-why-prevention-wins.html): Detection-only tools can’t stop attacks. Learn why prevention-first, secure-by-design systems like Edera are redefining modern cloud security. (999 words) - [Why Edera Rewrote Xen’s Control Plane in Rust](/content/stories/rust-or-bust-our-rewrite-of-the-xen-control-plane/index.html): Discover why Edera rewrote the Xen control plane in Rust—and how memory safety gives us a real security edge in container and GPU infrastructure. (1,147 words) - [The Hidden Risks of Legacy Code in Modern Systems](/content/stories/the-problems-of-legacy-code/index.html): Legacy code risks security. Edera Protect delivers memory-safe, hardened isolation to stop breaches and protect critical workloads. (668 words) - [Meet Sprout: A Rust-Based Bootloader for Cloud-Native](/content/stories/sprout-the-rust-powered-open-source-bootloader-for-the-cloud-native-era.html): Discover Sprout by Edera — the Rust-built, open-source bootloader delivering sub-second boot speeds, cloud-native simplicity, and memory-safe security. (574 words) - [Using eBPF with Edera – Edera](/content/docs/guides/ebpf/using-ebpf/index.html): How to verify eBPF support in an Edera zone kernel using bpftool., How to verify eBPF support in an Edera zone kernel using bpftool. (368 words) - [Resource utilization with Edera – Edera](/content/docs/guides/resource-utilization/index.html): This guide provides an overview of how Edera improves resource utilization, including CPU and memory utilization. We will show how you can use the protect CLI to view resource utilization and manually adjust the resources available to your workloads. For more information about how Edera does memory ballooning, see our guide. For the Kubernetes-native equivalent that exposes Zone capacity to the scheduler through Dynamic Resource Allocation, see the DRA Driver for Edera Zones guide., This guide provides an overview of how Edera improves resource utilization, including CPU and memory utilization. We will show how you can use the protect CLI to view resource utilization and manually adjust the resources available to your workloads. For more information about how Edera does memory ballooning, see our guide. For the Kubernetes-native equivalent that exposes Zone capacity to the scheduler through Dynamic Resource Allocation, see the DRA Driver for Edera Zones guide. (432 words) - [How Edera Delivers Enterprise-Grade Security](/content/stories/security-built-into-our-dna-how-edera-achieves-enterprise-grade-protection.html): Discover how Edera’s hardened runtime and Trail of Bits audit prove that enterprise-grade security isn’t an add-on—it’s built into our DNA.” (1,306 words) - [NUMA Explained: Why Memory Distance Slows Your VMs](/content/stories/numa-part-1-cores-memory-and-the-distance-between-them.html): Why two identical VMs on the same host can perform 20% differently — and what NUMA topology in Xen-based virtualization actually costs you. (4,060 words) - [LLM Zero-Day Discovery: Why Container Isolation Fails](/content/stories/the-price-of-a-zero-day-vulnerability-is-an-api-call.html): LLMs now find kernel zero-days at scale. Here's why container isolation fails and why hardware-enforced workload isolation must become the default. (1,021 words) - [Kernel Memory Blindspots in Kubernetes AI Workloads](/content/stories/what-every-cloud-native-engineer-needs-to-know-about-kernel-memory.html): cgroups memory metrics hide what the kernel actually knows. Learn why MemAvailable is invisible in containers and why AI agents need dedicated kernels to surfac (1,623 words) - [Kaylin Trychon | Edera](/content/authors/kaylin-trychon/index.html): Kaylin Trychon a seasoned cybersecurity executive specializing in cloud native security, threat intelligence and open source software security. She writes on AI security, sovereign AI infrastructure, container escape vulnerabilities, and what enterprise-grade protection actually requires. (185 words) - [Styrolite: A New Rust-Built Linux Container Runtime](/content/stories/styrolite/index.html): We're open sourcing our programmatic low-level container runtime, Styrolite (890 words) - [Ariadne Conill | Edera](/content/authors/ariadne-conill/index.html): Ariadne Conill has spent years contributing to open source infrastructure projects including Alpine Linux and Debian. She writes on isolation architecture, container security primitives, and the failure modes of shared-kernel environments. (146 words) - [Edera Team | Edera](/content/authors/edera-team/index.html): Edera reimagines container runtime from the foundation up, bringing resource optimization to workloads without disrupting developer workflows. Our approach bridges the gap between how containers ship and how they should run. (184 words) - [Docker-in-Docker Security Risks and How to Escape Them](/content/stories/the-docker-in-docker-trap-escaping-privileged-container-hell-with-edera.html): Docker-in-Docker forces a choice between socket mounting and privileged containers. Edera eliminates both risks with hardware-enforced workload isolation. (1,770 words) - [Getting started – Edera](/content/docs/getting-started/index.html): Edera runs every container in its own VM. You get hypervisor-level isolation with one line of Kubernetes config—no image changes, no rebuilds, no new workflows. See it in action The interactive demo shows Edera blocking a real container escape attack. No install required—just sign up and watch it work., Edera runs every container in its own VM. You get hypervisor-level isolation with one line of Kubernetes config—no image changes, no rebuilds, no new workflows. See it in action The interactive demo shows Edera blocking a real container escape attack. No install required—just sign up and watch it work. (194 words) - [Why Hybrid Cloud Is Back for AI Infrastructure](/content/stories/why-hybrid-clouds-are-making-a-comeback-with-ai-infrastructure.html): Why enterprises are returning to hybrid cloud for secure, cost-efficient, AI infrastructure: from GPU orchestration to data sovereignty. (1,052 words) - [Run Claude Code in YOLO Mode Safely with Kernel-Level Isolation](/content/stories/yolo-mode-for-ai-agents-without-the-yolo-running-claude-code-with-kernel-isolation.html): Let Claude Code run unrestricted—without risk. Learn how kernel isolation with Edera contains AI agent blast radius in Kubernetes. (1,396 words) - [How to Secure Agentic AI With Hardened Runtime Isolation](/content/stories/securing-agentic-ai-systems-with-hardened-runtime-isolation.html): Protect agentic AI with true runtime isolation. Prevent prompt injection, tool misuse, and container escapes using Edera’s hardened runtime. (1,176 words) - [Edera's architecture – Edera](/content/docs/technical-overview/architecture/index.html): Edera architecture overview KVM architecture How Edera’s components fit together , Edera architecture overview KVM architecture How Edera’s components fit together (10 words) - [Paravirtualization Explained Simply](/content/stories/what-the-f-ck-is-paravirtualization/index.html): Paravirtualization explained: how Edera uses it to deliver fast startup, hardened isolation, and secure performance across any cloud. (1,222 words) - [Marina Moore | Edera](/content/authors/marina-moore/index.html): Marina Moore holds a PhD in software supply chain security from NYU and is a maintainer of TUF, in-toto, Sigstore, and Uptane. A co-chair of CNCF TAG Security, she writes on container isolation, confidential computing, and multi-tenant cloud security. (159 words) - [Container Isolation Explained for Kubernetes and Beyond](/content/stories/what-the-f-ck-is-container-isolation-security-in-kubernetes-beyond.html): Discover container isolation: how Linux, virtualization, and hypervisors secure Kubernetes workloads and prevent container escapes. (1,335 words) - [How Edera Isolates Kubernetes by Design](/content/stories/were-isolating-kubernetes/index.html): Kubernetes isn’t isolating your workloads by default, but Edera Protect solves this problem at a runtime level. (1,739 words) - [Lewis Denham-Parry | Edera](/content/authors/lewis-denham-parry/index.html): Lewis Denham-Parry bridges the gap between developers and cloud-native security. He writes on Kubernetes isolation, MCP security risks, and what effective AI infrastructure sandboxing actually looks like. (75 words) - [Celebrating LGBTQ+ Innovators in Tech History](/content/stories/we-have-always-been-here-celebrating-lgbtq-icons-from-tech-history.html): LGBTQ+ people have been making incredible contributions to technology and society, let's meet a few of those icons from the history of tech. (1,674 words) - [What Engineers Should Know About Container Isolation](/content/stories/what-we-wish-we-knew-about-container-isolation/index.html): Rethink container security. True isolation—not just patching or scanning—may be the missing key to securing modern cloud infrastructure. (1,282 words) - [Alex Zenla | Edera](/content/authors/alex-zenla/index.html): Alex Zenla is co-founder and CTO of Edera, where she leads development of a container-native type-1 hypervisor built in Rust. She writes on GPU security, Kubernetes isolation, and the architectural shifts redefining secure cloud infrastructure. (166 words) - [Multitenancy Explained: Secure and Efficient Containers](/content/stories/what-the-f-ck-is-multitenancy-secure-efficient-containers-explained.html): Learn what multitenancy really means, why it matters for containers, and how Edera delivers secure efficiency without shared vulnerabilities. (1,120 words) - [Modern Cloud Attacks Exploit Trust Models, Not Break-Ins](/content/stories/when-attackers-blend-in-why-visibility-isnt-containment.html): Modern attackers exploit implicit trust, not exploits. Learn why observability can’t replace containment in today’s cloud infrastructure. (968 words) - [Emily Long | Edera](/content/authors/emily-long/index.html): Emily Long is co-founder of Edera and a leader focused on inclusive team-building. She writes on leadership, open source culture, and the people shaping cloud-native infrastructure. (76 words) - [Why Production-Grade Sandbox Isolation Took Two Years to Build](/content/stories/two-years-building-the-sandbox-everyone-suddenly-needs-for-ai.html): A behind-the-scenes look at why real container and AI agent isolation takes years—not weekends—and what production-grade sandboxing actually requires. (1,250 words) - [Isolation Without Compromise: A Recipe for Security](/content/stories/the-rce-cipe-for-platform-security-isolation-without-compromise.html): What happens when you want to offer a platform where customers can run any code, anywhere, without compromising your entire infrastructure? (510 words) - [Jed Salazar | Edera](/content/authors/jed-salazar/index.html): Jed Salazar is an expert in cloud-native security with a focus on container isolation, eBPF, and supply chain security. A KubeCon speaker and published author, he writes on runtime security, Kubernetes trust boundaries, and GPU attack surfaces. (168 words) - [AI agent sandboxing – Edera](/content/docs/technical-overview/concepts/ai-agent-isolation/index.html): Why AI agents need hardware-level sandboxing and how Edera zones provide secure isolation for autonomous AI workloads., Why AI agents need hardware-level sandboxing and how Edera zones provide secure isolation for autonomous AI workloads. (1129 words) - [Edera Turns Two: GPU Security, KVM, and What's Next](/content/stories/two-years-of-edera/index.html): Two years building secure computing infrastructure. Here's what Edera shipped, where the market moved, and what comes next for GPU and KVM workloads. (955 words) - [Ann Wallace | Edera](/content/authors/ann-wallace/index.html): Ann Wallace is the VP of Customer Experience at Edera, with a background in security and cloud leadership across some of tech's most demanding environments. She speaks regularly at conferences on compliance, container security, and making security education actually land. When she's not debating isolation boundaries, you'll find her trail running somewhere in the Pacific Northwest with her dirtbag dog, Cedar. (102 words) - [Explaining Remote Attestation in Confidential Computing](/content/stories/remote-attestation-in-confidential-computing-explained.html): Learn how remote attestation in confidential computing verifies trust in cloud environments using cryptographic proof. (1,197 words) - [Théo Pavlich | Edera](/content/authors/theo-pavlich/index.html): Théo Pavlich builds GTM and operational systems for early-stage infrastructure companies. They write on the communities and histories that shape the technology industry. (54 words) - [Privacy Policy | Edera](/content/privacy-policy/index.html): Learn how Edera protects your privacy. We collect and handle data responsibly to ensure transparency, security, and trust across our platform. (2,385 words) - [Steven Noonan | Edera](/content/authors/steven-noonan/index.html): Steven Noonan brings a background in cross-platform systems development and performance optimization. He writes on OCI container image internals and low-level runtime behavior. (114 words) - [Shared Linux Kernels: The Cloud Security Risk We Ignore](/content/stories/the-shared-kernel-is-the-real-problem-in-container-security.html): Containers don’t isolate what matters most. Learn why shared Linux kernels are the weakest link in cloud native security—and why patching isn’t enough. (1,179 words) - [Why Data Warehouses Need Isolation for Untrusted Code](/content/stories/why-cloud-data-warehouses-must-run-untrusted-code-in-isolation.html): AI-driven code inside data warehouses introduces new attack vectors. Learn why true isolation is now essential for security and compliance. (850 words) - [Edera Raises $15M to Advance Cloud and AI Security](/content/stories/series-a/index.html): Announcing $15 million in Series A funding for Edera, led by M12, Microsoft's Venture Fund, with participation from Mantis VC and In-Q-Tel (IQT). (807 words) - [The GPU-on-Kubernetes Security Risk Nobody's Talking About](/content/stories/i-looked-at-the-gpu-stack-at-kubecon-and-now-i-cant-sleep.html): A layer-by-layer teardown of the GPU-on-Kubernetes stack, from ring-0 kernel modules to RDMA data planes, and why the threat model demands structural isolation (2,129 words) - [Why Showing Up Matters in Tech and Community](/content/stories/showing-up-matters-reflections-on-pride-allyship-and-community.html): What does meaningful allyship look like — in life, at work, and within the tech community I care so much about? (1,217 words) - [Kavi Daula | Edera](/content/authors/kavi-daula/index.html): Kavi Daula leads engineering with a focus on impactful infrastructure technology. She writes on container runtimes, security for regulated environments, and why detection alone isn't containment. (126 words) - [What Zones Are and How Edera Uses Them](/content/stories/what-the-f-ck-is-a-zone-secure-container-isolation-with-edera.html): Discover what zones are and how Edera delivers secure, high-performance container isolation without the cost or overhead of virtual machines. (650 words) - [Xen vs. KVM: Why Xen Provides Stronger Security](/content/stories/xen-vs-kvm-why-xen-offers-superior-security-in-virtualization.html): Discover why Xen’s microkernel design and strong isolation make it the top choice for secure virtualization over KVM. (1,094 words) - [Securing the AI Grid: Why Telecom Edge Isolation Matters](/content/stories/the-ai-grid-is-coming-to-cell-sites-so-are-the-attackers.html): Nation-state actors have compromised telecom networks. As AI inference scales to 100,000 cell sites, workload isolation is the missing layer. (1,193 words) - [What a Hardened Runtime Is and Why It Matters](/content/stories/what-the-f-ck-is-a-hardened-runtime-the-future-of-container-security.html): Learn why sandboxes fail and how hardened runtimes redefine container security with true hypervisor isolation, performance, and built-in protection. (643 words) - [Production AI Agent Sandboxing for Secure Infrastructure](/content/stories/what-ai-agent-sandboxing-means-for-production-infrastructure.html): AI agent sandboxing in production requires infrastructure-level isolation. Learn how to reduce blast radius for autonomous agents. (720 words) - [How to Secure Agentic AI Without Sacrificing Performance](/content/stories/performant-isolation-for-secure-ai-agents/index.html): Learn how strong isolation enables secure, high-performance agentic AI, with no performance penalty over shared-kernel containers or Docker. (615 words) - [Confidential Computing & Edera: Stronger Together | Edera](/content/use-case/confidential-computing/index.html): Confidential computing protects data in use with TEEs — but hardware lock-in and app rewrites slow adoption. See how Edera's hypervisor isolation complements confidential computing without the tax. (866 words) - [Edera Now Supports Azure Linux and Bare-Metal AI](/content/stories/product-update-now-on-azure-linux-plus-bare-metal-ai-performance-and-deeper-security.html): Edera brings Bare-Metal AI performance and hardened security to Azure Linux—eliminating tradeoffs between speed, safety, and simplicity. (891 words) - [Dan Fernandez | Edera](/content/authors/dan-fernandez/index.html): Dan Fernandez is a product leader at the intersection of machine learning and cybersecurity, with experience at CrowdStrike and Chainguard. He writes on AI infrastructure security, GPU runtime risks, and agentic AI systems. (150 words) - [SPIFFE, SPIRE & Zero Trust Without Confidential Hardware](/content/stories/open-standards-and-zero-trust-on-commodity-hardware.html): How SPIFFE and SPIRE enable zero trust workload identity and isolation—without relying on specialized confidential computing hardware. (1,518 words) - [Why Isolation Stops NVIDIA AI Vulnerabilities Cold](/content/stories/the-principle-of-isolation/index.html): While everyone is distracted on social media with the CUPS vulnerability, Wiz researchers dropped the mic with a massive GPU vulnerability that puts all AI infr (840 words) - [Container Escape Benchmark: Zero Escapes Against Edera Zones](/content/stories/llms-escaped-docker-18-times-zero-escapes-on-edera/index.html): We ran every SandboxEscapeBench scenario on a live EKS cluster. Standard Docker: 18/18 exploitable. Edera Zones: zero successful escapes. (1,992 words) - [Alexander Merritt | Edera](/content/authors/alexander-merritt/index.html): Alexander Merritt specializes in operating systems, computer architecture, and multi-core memory systems. He writes on hypervisor security and the foundations of container isolation. (68 words) - [AI Patching Isn't Enough: The Case for Resilient Infrastructure](/content/stories/washington-is-betting-on-faster-patching-thats-not-enough.html): The White House AI security EO gets the threat right but misses the harder fix: infrastructure that contains exploits by design, not just patches them faster. (1,013 words) - [Confidential Computing Explained: How Encrypted Execution Really Works](/content/stories/what-is-confidential-computing/index.html): Learn what confidential computing really is, how TEEs encrypt data in use, and why it matters for securing workloads in untrusted environments. (742 words) - [What the Guillotine Paper Means for AI Hypervisors](/content/stories/rethinking-ai-hypervisors-for-modern-ml-workloads-lessons-from-the-guillotine-paper.html): What if AI containment isn't the answer? We explore architectural insights from the Guillotine paper and rethink hypervisors for machine learning. (860 words) - [Two Escalation Chains, One Shared-Kernel Flaw: AI Breach Analysis](/content/stories/cya-contain-your-architecture-mitigating-the-hugging-face-breach.html): An AI agent escaped two "isolated" sandboxes at OpenAI and Hugging Face via shared-kernel escalation. See how hardware-enforced Zones stop it. (1,573 words) - [Run Untrusted Code Safely with Styrojail Sandbox](/content/stories/new-functionality-comes-to-ederas-open-source-sandboxing-tool-styrolite.html): Run AI agents, browsers, and CLI tools safely with Styrojail, Edera’s open source sandbox for secure local container isolation. (629 words) - [Why Namespace Isolation Isn’t Security](/content/stories/when-virtual-doesnt-mean-secure-the-false-promise-of-namespace-based-isolation.html): Let's be clear about something that security experts have known for decades: Namespaces are not a security boundary. (429 words) - [Edge Workload Isolation When You Can't Patch the Kernel](/content/stories/edera-at-the-edge-running-untrusted-workloads-on-kernels-you-cannot-fix.html): Edge kernels don't get patched. Edera isolates each workload in its own kernel so a shared host vulnerability can't propagate across your entire fleet. (2,718 words) - [How Edera Accelerates Confidential Computing Adoption](/content/stories/mind-the-gap-how-edera-accelerates-confidential-computing.html): While confidential computing is powerful, its adoption faces challenges including hardware requirements, compatibility issues, and performance costs. (1,442 words) - [Kim Scott on Leadership, Culture, and Radical Candor](/content/stories/120-seconds-with-kim-scott/index.html): Join us as we interview cybersecurity experts, Edera team members, and people we admire to share stories that inform, inspire, and entertain you. (1,889 words) - [Edera vs runc on EKS: CPU, Memory & Startup Benchmarks](/content/stories/faster-than-runc-benchmarking-edera-on-amazon-eks/index.html): Benchmark results comparing Edera and runc on EKS. See CPU, memory, I/O, and pod startup performance for isolated microVM workloads. (1,606 words) - [Edera vs Firecracker: MicroVM vs Container Isolation](/content/edera-vs-firecracker/index.html): Compare Edera and Firecracker across microVM architecture, hardware virtualization requirements, Kubernetes integration, observability, GPU support, and multi-cloud portability. (595 words) - [Where to Find Edera at KubeCon North America 2025](/content/stories/edera-at-kubecon-cloudnativecon-north-america-2025/index.html): Meet Edera at KubeCon Atlanta! See how we secure containers, AI agents, and GPU workloads — and join us for Night at the Aquarium. (739 words) - [Edera vs gVisor | High-Performance Container Isolation](/content/edera-vs-gvisor/index.html): Compare Edera vs gVisor for container isolation. See why teams choose Edera for native performance, eBPF observability, GPU support, and production-ready security. (644 words) - [Meet Cedar Sunbeam: Edera’s Pawsitivity Pal](/content/stories/pawsitivity-pal-cedar-sunbeam/index.html): At Edera, we love sharing some pawsitivity! Meet Cedar Sunbeam (164 words) - [Strong Isolation That Also Cuts Cloud Costs](/content/stories/have-your-cake-and-eat-it-strong-isolation-while-reducing-cloud-spend.html): Imagine running multiple workloads on a single cloud instance—securely—while slashing your infrastructure expenses. That's not a fantasy. It's Edera Protect (1,180 words) - [Kubernetes Isolation With Full Observability and Autoscaling](/content/stories/edera-native-workload-intelligence-for-kubernetes/index.html): Hardware-enforced Kubernetes isolation that preserves HPA, accurate pod metrics, NUMA-aware GPU placement, and your existing monitoring stack. No trade-offs. (1,540 words) - [Why GPU Runtime Security Is Failing AI Clouds](/content/stories/gpu-runtime-security-why-ai-clouds-are-flying-blind.html): eBPF secures CPUs but is blind to GPU workloads. Discover why AI clouds face a hidden runtime security gap — and what it means for enterprises. (1,402 words) - [Edera for GPUs | Edera](/content/gpus/index.html): Edera for GPUs isolates and secures AI workloads without sacrificing performance. Prevent GPU data leaks and enable safe, multi-tenant AI infrastructure. (311 words) - [Edera 1.0 Launches With Hardened Runtime Security](/content/stories/announcing-edera-protect-1-0-now-generally-available.html): After less than a year of development, Edera for Containers has reached its 1.0 release, reimagining container infrastructure for the cloud native world (955 words) - [7 NVIDIA GPU Flaws That Put AI Infrastructure at Risk](/content/stories/7-critical-nvidia-gpu-vulnerabilities-expose-ai-systems-protect-your-infrastructure-now.html): A comprehensive guide to securing GPU infrastructure against newly discovered vulnerabilities through advanced isolation techniques - 5 minute read (803 words) - [Secure-by-Default Isolation for Privileged Containers](/content/stories/edera-makes-running-privileged-containers-safe-and-secure-by-default.html): Privileged containers have long been considered a security risk because they bypass many of the isolation mechanisms that normally protect host systems (1,311 words) - [Edera vs Kata Containers | Production Container Isolation for Kubernetes](/content/edera-vs-kata/index.html): Compare Edera vs Kata Containers for Kubernetes isolation. See why teams choose Edera for production-grade security, deep observability, simpler operations, and enterprise support. (637 words) - [Meet Daisy: Another Pawsitivity Pal](/content/stories/pawsitivity-daisy/index.html): At Edera, we love sharing some pawsitivity! Want to get in on sharing yours? Send us a bit about your Pawsitivity Pal and we’ll feature them on Edera & Friends! (106 words) - [AI Agents Explained: From Chatbots to Autonomous Systems](/content/stories/what-is-an-ai-agent-from-chatbots-to-autonomous-systems.html): AI agents don’t just answer—they act. Learn how agents think, use tools, and reshape automation across industries. (1,321 words) - [Kubernetes User Namespaces Don't Fix the Shared Kernel](/content/stories/kubernetes-finally-has-user-namespace-support-the-shared-kernel-problem-remains.html): Kubernetes v1.36 shipped user namespace GA. It's a real improvement. It also doesn't change the shared-kernel threat model. Here's what actually does. (1,571 words) - [Untrusted Code Execution Without the Risk | Edera](/content/use-case/untrusted-code-execution/index.html): Run integrations, plugins, and customer workloads without shared-kernel risk. Edera gives every container its own Linux kernel — full compatibility, true isolation. (1,000 words) - [Stephen Augustus on Open Source Leadership and Security](/content/stories/120-seconds-with-stephen-augustus/index.html): Stephen Augustus shares insights on open source, diversity in tech, and joining Edera’s Advisory Board. (1,272 words) - [Hardened Runtime: The New AI and Cloud Security Perimeter](/content/stories/hardened-runtime-the-new-security-perimeter-for-ai-cloud.html): Shift from detection to prevention with hardened runtime security for AI, cloud-native, and GPU workloads. (1,238 words) - [What the F--- Is That? | Edera](/content/blog/what-is-that/index.html): Learn complex tech the easy way. This series explains AI agents, multitenancy, confidential computing, container isolation, and more in plain English. (452 words) - [Dirty Frag: What It Is and Why It Matters for Container Security](/content/stories/dirty-frag-the-linux-kernel-exploit-that-turns-your-page-cache-against-you.html): Dirty Frag is a Linux kernel exploit that chains two CVEs to corrupt page cache and escalate to root. Here's what it is, who's affected, and what to do about it (1,703 words) - [Apple Validates Hypervisor-Isolated Containers—Why It Matters](/content/stories/apple-just-validated-hypervisor-isolated-containers-heres-what-that-means.html): Apple’s new Swift-based Containerization Framework brings hypervisor-isolated containers to macOS—raising security to the next level. (1,245 words) - [Edera Brings Zone Isolation to KVM Infrastructure](/content/stories/kvm-support-is-coming-to-edera/index.html): Edera is extending zone-based workload isolation to KVM this summer — no re-architecture required. Strong fault isolation where your infrastructure already runs (890 words) - [Edera Launches Hardened Runtime Standard for AI Security](/content/stories/hardened-runtime-standard-for-ai-and-app-security/index.html): Edera today announced it is claiming the new "Hardened Runtime" category for AI and application security, declaring an end to "move fast and break things" (1,018 words) - [Kata Containers CVE-2026-24834: MicroVM Trust Failure](/content/stories/cve-2026-24834-when-trusting-the-guest-goes-wrong/index.html): A 9.4 CVE in Kata Containers exposes a core microVM isolation flaw: trusting the guest. What it reveals about secure microVM design. (1,246 words) - [CrackArmor: AppArmor Flaws Expose Linux Kernel Risk](/content/stories/crackarmor-when-linux-armor-quietly-cracked/index.html): AppArmor's CrackArmor advisory reveals a confused-deputy flaw and kernel memory bugs that chain into full root privilege escalation on Linux systems. (1,164 words) - [Secure Multi-Tenant Isolation for Kubernetes | Edera](/content/use-case/multi-tenant-isolation/index.html): Every container shares the same kernel. Edera fixes that. Per-pod kernel isolation for Kubernetes — no container escapes, no blast radius, no cluster sprawl. (1,032 words) - [Confidential Computing Explained Clearly](/content/stories/demystifying-confidential-computing/index.html): Explore the real-world tradeoffs, costs, and limitations of confidential computing, from TEEs to confidential AI and evolving security challenges. (1,431 words) - [A New Model for Kubernetes Trust Boundaries and Isolation](/content/stories/containers-that-actually-contain-a-new-era-in-kubernetes-trust-boundaries.html): Ten years into Kubernetes, the topic of container security is just as relevant as ever. (795 words) - [Joe Beda on Kubernetes, Security, and Community Insights](/content/stories/120-seconds-with-joe-beda/index.html): Join us as we interview cybersecurity experts, Edera team members, and imaginary friends to share stories that inform, inspire, and entertain you. (1,030 words) - [Edera Joins CNCF and Linux Foundation Ahead of KubeCon](/content/stories/edera-joins-cncf-linux-foundation-and-heads-to-kubecon-cloudnativecon-london.html): The Edera team is packing our bags and heading to London for KubeCon + CloudNativeCon Europe 2025! (1,213 words) - [Edera Performance Benchmarks: Security Without Sacrifice](/content/stories/security-without-sacrifice-edera-performance-benchmarking.html): We benchmark Edera Protect against industry alternatives to demonstrate how our technology delivers security without compromising performance. (924 words) - [How Rust + Xen Shrink the Hypervisor Attack Surface](/content/stories/edera-reduces-the-hypervisor-attack-surface-with-rust-and-xen.html): See how Edera reduces the hypervisor attack surface using Rust and Xen—achieving up to 94% less privileged code and secure, minimal infrastructure. (739 words) - [Edera’s $5M Seed Fuels Secure-By-Design Kubernetes](/content/stories/icymi-edera-seed-funding-for-the-worlds-only-secure-by-design-kubernetes-and-ai-solution.html): Edera raised $5M in seed funding to bring the world’s only secure-by-design Kubernetes and AI solution to market (682 words) - [Edera Delivers Secure Workload Isolation for Federal Systems](/content/stories/edera-brings-production-grade-workload-isolation-to-federal-market.html): Edera joins AWS GovCloud and Carahsoft to deliver secure-by-design workload isolation that meets FedRAMP High and DoD compliance requirements. (887 words) - [How Edera Neutralizes the Chaotic Deputy Problem](/content/stories/finding-xen-in-the-chaos-ederas-isolation-makes-chaotic-deputy-irrelevant.html): Edera users stay safe from Chaos Mesh’s “Chaotic Deputy” CVEs. Learn how secure-by-design isolation stops command injection and container escapes. (442 words) - [How Edera Integrates With eBPF for Better Security](/content/stories/edera-supports-ebpf/index.html): Edera now supports eBPF—combining deep kernel observability with true workload isolation for better threat detection without alert fatigue. (669 words) - [MCP Flaw Reveals Major AI Development Security Gaps](/content/stories/mcp-vulnerability-exposes-ai-dev-security-gaps/index.html): Critical AI dev tool flaw (CVSS 9.4) enables remote code execution. Here's how untrusted code is reshaping enterprise security priorities. (1,200 words) - [Kata, gVisor, or Firecracker? Container Isolation Guide](/content/stories/kata-vs-firecracker-vs-gvisor-isolation-compared/index.html): Comparing Kata Containers, Firecracker, and gVisor? See the tradeoffs in performance, isolation, and Kubernetes integration and what comes next. (1,083 words) - [SOC 2 Security Theater: Why Compliance Isn't Real Security](/content/stories/who-gives-a-soc-2-the-truth-about-soc-2-security-theater.html): SOC 2 proves controls existed, not that systems are secure. Here’s why compliance theater happens and how engineering teams build real security instead. (884 words) - [How OpenPaX Brings Memory Safety Back to Linux Apps](/content/stories/edera-restores-security-benefits-for-linux-application-memory-safety-with-openpax.html): OpenPaX offers open source mitigations for runtime memory safety errors, unlocking developer access to critical security features while saving companies (544 words) - [2024 Exploitation Trends and the Shift Toward Prevention](/content/stories/2024-vulnerability-exploitation-trends-moving-beyond-whack-a-mole-security.html): The landscape of vulnerability exploitation continues to evolve at an alarming pace, with new data revealing the scale and sophistication of current threats (707 words) - [The Vine Blog | Edera](/content/stories/index.html): Explore insights from Edera on container isolation, AI security, and hardened runtimes. Innovation meets infrastructure reality in every story. (453 words) - [MCP Security Risks Explained: Securing AI Agents with Isolation](/content/stories/mcp-security-risks-why-ai-infrastructure-needs-isolation.html): MCPs empower AI agents—but expose risk. Learn how hypervisor-grade isolation protects enterprise AI infrastructure from MCP vulnerabilities. (1,054 words) - [Events | Edera](/content/events/index.html): Meet Edera at upcoming conferences and events, or watch past webinars on Kubernetes, container security, multitenancy, and cloud-native infrastructure. (315 words) - [AI Agent Sandboxing | Edera](/content/use-case/ai-agent-sandboxing/index.html): Sandbox AI agents without syscall allowlists. Each agent runs in its own kernel via a Type-1 hypervisor. Full Linux compatibility, contained blast radius. (821 words) - [AI Agent Sandbox vs Containers: What Actually Isolates?](/content/stories/what-is-an-ai-agent-sandbox/index.html): Learn what an AI agent sandbox is, why containers fall short, and how production-grade isolation protects Kubernetes from untrusted AI code. (1,247 words) - [Rethinking the Container Security Status Quo](/content/stories/escaping-the-container-status-quo/index.html): Edera ends container escapes by removing the shared kernel, delivering secure, isolated workloads on any hardware with no performance loss. (834 words) - [How to Future-Proof AI Infrastructure at Scale](/content/stories/future-proofing-ai-infrastructure-lessons-from-past-mistakes.html): Learn how to future-proof your AI infrastructure with lessons from past container security and performance challenges (880 words) - [A Runtime Built for Highly Regulated and Secure Systems](/content/stories/finally-a-container-runtime-built-for-highly-regulated-systems.html): Edera brings VM-level isolation to containers without sacrificing performance or usability—ideal for PCI, FedRAMP, NIST, and other compliance needs. (1,077 words) - [Apple PCC vs. Confidential Computing: What’s the Difference?](/content/stories/apples-private-cloud-compute-vs-confidential-computing.html): Compare Apple’s Private Cloud Compute and confidential computing. Learn their threat models, similarities, and key differences. (1,201 words) - [Edera + Falco: A Better Model for Cloud-Native Detection](/content/stories/edera-falco-for-cloud-native-security/index.html): Edera integrates with Falco to deliver full runtime visibility & threat detection for microVM workloads, closing the observability gap in cloud-native security (891 words) - [NVIDIA Toolkit Flaw Shows Why Strong Isolation Matters](/content/stories/critical-nvidia-container-toolkit-vulnerability-highlights-the-need-for-strong-isolation.html): CVE-2024-0132 in NVIDIA's Container Toolkit exposes a fundamental weakness in traditional container security: the need for strong isolation (485 words) - [How Edera Enhances Confidential Computing Workloads](/content/stories/edera-and-confidential-computing-stronger-together/index.html): Explore how Edera enhances confidential computing with flexible, hypervisor-based isolation for secure, scalable cloud workloads. (695 words) - [Edera’s Isolation Blocks CVE-2025-23266 Escapes](/content/stories/how-edera-eliminates-cve-2025-23266-container-escapes.html): Avoid CVE-2025-23266 risks. See how Edera's hypervisor-based container isolation stops NVIDIA Container Toolkit escapes before they start. (651 words) - [AI Security Begins at the Infrastructure Layer](/content/stories/ai-security-starts-with-infrastructure-not-tools/index.html): AI security isn't a tooling problem — it's an infrastructure one. Learn why runtime protection and isolation matter more than DLP band-aids. (1,129 words) - [Edera Raises $5M for Secure-by-Design Kubernetes Security](/content/stories/edera-raises-5m-seed-round/index.html): Edera, the world’s only secure-by-design Kubernetes and AI solution, today announced it has raised $5 million in a seed round (1,335 words) - [Edera and Minimus Partner for Container Security](/content/stories/edera-and-minimus-partner-to-deliver-end-to-end-container-security-for-critical-infrastructure.html): Edera and Minimus unite to deliver hardened runtime isolation and near-zero CVE images for enterprises operating critical infrastructure in the AI threat era. (959 words) - [Building Lasting Security Foundations With Edera](/content/stories/cybersecurity-awareness-month-start-secure-and-stay-secure-with-edera.html): Let’s face it: security in the cloud-native world has become more complex than ever before. (794 words) - [Why It’s Time to Rebuild Kubernetes Foundations](/content/stories/kubecon-north-america-2025-a-decade-in-its-time-to-rebuild-the-foundations.html): KubeCon 2025 exposed growing pain points in Kubernetes—security gaps, tooling complexity, and rising observability costs. Here’s why it’s time to rebuild the fo (555 words) - [Why GPUs Are the Weakest Link in AI Security](/content/stories/why-gpus-are-the-weak-link-in-ai-security/index.html): GPUs power AI, but lack CPU-grade isolation. Learn why GPU security gaps threaten multitenant AI workloads and how to close them. (988 words) - [Edera Commits to CISA’s Secure by Design Principles](/content/stories/edera-makes-the-cisa-secure-by-design-pledge/index.html): Edera has signed the CISA “Secure By Design” pledge to reaffirm our commitment to secure-by-design Kubernetes and AI containers (357 words) - [Edera for GPUs: Secure Multi-Tenant GPU Infrastructure](/content/stories/introducing-edera-for-gpus-and-the-era-of-continuous-compute-delivery.html): GPU clouds are stuck with 30-min spin-ups and risky single-tenancy. Edera for GPUs delivers hardware-enforced isolation, elastic workloads, and fast boot times. (701 words) - [Why Psychological Safety Shapes Strong Security Teams](/content/stories/cybersecurity-industrys-vulnerability-why-psychological-safety-matters.html): Edera's CEO talks about psychological safety and mental health, and why this is critically important to our security infrastructure. (733 words) - [Rob Gil on AI Security, Strategy, and Board-Level Priorities](/content/stories/120-seconds-with-new-edera-board-advisor-rob-gil/index.html): Join us as we interview cybersecurity experts, friends of Edera, and people we admire to share stories that inform, inspire, and entertain you. (935 words) - [How Edera Turns Container Alerts Into Actionable Insights](/content/stories/context-changes-everything-how-edera-transforms-container-security-alerts-from-panic-to-precision.html): Most organizations invest millions in container security but still have to ask if container alerts without context are critical breaches or routine noise. (754 words) - [Defining Container Isolation for Modern Multi-Tenant Cloud](/content/stories/defining-container-isolation-for-the-multi-tenant-cloud-era.html): It's time for the industry to align on a clear definition of "strong isolation" that can protect cloud-native applications from the threats of tomorrow. (538 words) - [Press & Events | Edera](/content/press-events/index.html): Explore the latest from Edera, including events, press releases, and industry news. Stay informed on how hardened runtime isolation is reshaping security. (284 words) - [Why Kubernetes Overprovisioning Burns Cloud Budget](/content/stories/kubernetes-dirty-secret-why-youre-burning-cash-on-containers.html): While cloud computing competition is driving lower cloud spend, Kubernetes, meant to improve resource utilization, ultimately only negates savings. (715 words) - [Footer Form Integration](/content/footer-form-integration/index.html) (90 words) - [New Tool Shows Whether You’re Safe From Container Escapes](/content/stories/new-container-security-tool-tells-devops-and-platform-engineers-if-theyre-protected-against-escapes.html): Edera releases ‘Am I Isolated,’ an open source container security benchmark and Rust-based container runtime scanner (541 words) - [Edera for Containers | Edera](/content/containers/index.html): Edera for Containers delivers full isolation and near-native performance. Secure Kubernetes and containerized workloads with hardened runtime protection. (314 words) - [Careers | Edera](/content/careers/index.html): Join Edera and help reinvent secure computing. We are building the future of container infrastructure with speed, vision, and collaboration. (54 words) - [Boot a VM image as a zone – Edera](/content/docs/guides/standalone/vm-images/index.html): Run an unmodified raw or qcow2 VM disk image directly as an Edera zone on a KVM-backed host., Run an unmodified raw or qcow2 VM disk image directly as an Edera zone on a KVM-backed host. (619 words, Jul 22, 2026) - [Zone networking (standalone, no Kubernetes) – Edera](/content/docs/guides/standalone/zone-networking/index.html): How Edera zone networking works outside of Kubernetes: ARP proxying, static routes, nftables, and host-level traffic filtering., How Edera zone networking works outside of Kubernetes: ARP proxying, static routes, nftables, and host-level traffic filtering. (928 words, Feb 17, 2026) - [Running Edera (no Kubernetes required) – Edera](/content/docs/guides/standalone/no-kubernetes/index.html): Learn how to launch zones and workloads using the Edera protect CLI without Kubernetes., Learn how to launch zones and workloads using the Edera protect CLI without Kubernetes. (507 words, Jul 22, 2025) ## About Pages - [About | Edera](/content/about/index.html): Edera is redefining secure computing with hardened runtime isolation. Our mission is to make infrastructure simple, efficient, and secure by design for everyone. (617 words) - [Contact | Edera](/content/contact/index.html): Get in touch with the Edera team. Whether you are exploring hardened runtimes or securing Kubernetes at scale, we are here to help you move fast and stay safe. (73 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives