System requirements
Raft coordinates unprivileged Linux containers across two environments: dedicated Incus workspace hosts, and a controller running the Raft CLI.
Workspace host requirements
Each workspace host must be a dedicated physical machine or virtual instance:
| Component | Requirement | Notes |
|---|---|---|
| Architecture | ARM64 or AMD64 | Workspaces run native binaries matching the host CPU architecture. |
| Operating system | Ubuntu 22.04 LTS or 24.04 LTS | The deployer installs Incus 6.0 LTS and nftables bridge isolation rules. |
| CPU | At least 2 CPU cores | Capacity calculations reserve 1 CPU core for the host OS and services (an advisory estimate, not an enforced host reservation). |
| RAM | At least 8 GiB | Sizing calculations reserve the larger of 2 GiB or 10% of host RAM (an advisory estimate, not an enforced host reservation). |
| Free disk | At least 80 GiB on host disk | The deployer provisions a 60 GiB dedicated Btrfs pool (raft-data). |
Host CPU and RAM reserves are advisory estimates for raft limits, not enforced cgroup locks.
Dedicated host requirement
Do not deploy Raft on hosts with existing Incus storage pools or shared virtualization workloads. Deployment configures dedicated nftables rules, storage pools, and system services.
Host access and permissions
- SSH access: SSH access with passwordless
sudo(sudo -n true). - Security model: Single operator with root access. Deploy only on trusted hardware and networks.
- Network connectivity: Outbound internet for Debian packages, Incus releases, and container images. Inbound SSH from the controller. No public Incus listener or cloud account needed.
Controller machine requirements
The controller is your local workstation, developer machine, or CI runner:
| Component | Requirement | Notes |
|---|---|---|
| Operating system | Linux | Controller CLI commands invoke standard Linux utilities. |
| Python | Python 3.11 or newer | Required to run the raft CLI tool. |
| Toolchain | git, uv, OpenSSH client (ssh), scp | uv manages the Python environment; OpenSSH provides the transport. |
| Network | Network route to host SSH targets | Batch SSH commands must connect without interactive password prompts. |
Next step
Proceed to Installation and setup to install the CLI, configure inventory, provision Incus, and acquire a workspace image.