raft / docs

System requirements

Raft coordinates unprivileged Linux containers across two environments: dedicated Incus workspace hosts, and a controller running the Raft CLI.

Workspace host requirements

Each workspace host must be a dedicated physical machine or virtual instance:

ComponentRequirementNotes
ArchitectureARM64 or AMD64Workspaces run native binaries matching the host CPU architecture.
Operating systemUbuntu 22.04 LTS or 24.04 LTSThe deployer installs Incus 6.0 LTS and nftables bridge isolation rules.
CPUAt least 2 CPU coresCapacity calculations reserve 1 CPU core for the host OS and services (an advisory estimate, not an enforced host reservation).
RAMAt least 8 GiBSizing calculations reserve the larger of 2 GiB or 10% of host RAM (an advisory estimate, not an enforced host reservation).
Free diskAt least 80 GiB on host diskThe deployer provisions a 60 GiB dedicated Btrfs pool (raft-data).

Host CPU and RAM reserves are advisory estimates for raft limits, not enforced cgroup locks.

Dedicated host requirement

Do not deploy Raft on hosts with existing Incus storage pools or shared virtualization workloads. Deployment configures dedicated nftables rules, storage pools, and system services.

Host access and permissions

  • SSH access: SSH access with passwordless sudo (sudo -n true).
  • Security model: Single operator with root access. Deploy only on trusted hardware and networks.
  • Network connectivity: Outbound internet for Debian packages, Incus releases, and container images. Inbound SSH from the controller. No public Incus listener or cloud account needed.

Controller machine requirements

The controller is your local workstation, developer machine, or CI runner:

ComponentRequirementNotes
Operating systemLinuxController CLI commands invoke standard Linux utilities.
PythonPython 3.11 or newerRequired to run the raft CLI tool.
Toolchaingit, uv, OpenSSH client (ssh), scpuv manages the Python environment; OpenSSH provides the transport.
NetworkNetwork route to host SSH targetsBatch SSH commands must connect without interactive password prompts.

Next step

Proceed to Installation and setup to install the CLI, configure inventory, provision Incus, and acquire a workspace image.

On this page