EVE-OS
The Open, Secure OS Enterprises Need to Scale at the Edge
What is EVE-OS?
EVE-OS is the open source operating system at the foundation of the ZEDEDA Edge Platform. Curated by the Linux Foundation, it delivers a secure, vendor-neutral base purpose-built for edge deployments. By virtualizing hardware and protecting workloads, EVE-OS makes it possible to run any application—containerized, virtualized, or legacy—with confidence at scale. Unlike traditional operating systems, EVE-OS abstracts hardware resources to provide a consistent, secure execution environment across diverse workloads and device types.
EVE-OS follows a strict zero-trust execution model: edge devices maintain hardware-backed identities using TPM, do not expose remote login or shell access of any kind, and operate on a pull-based control flow, meaning the controller cannot push workloads or commands into the device. This architecture eliminates an entire class of attacks and ensures each node remains independently verifiable and secure.
Its design is anchored by four key principles that define how it delivers security, flexibility, and openness at scale:
- Open by Design: Publicly governed by LF Edge, eliminating vendor lock-in
- Secure by Default: Zero Trust architecture with measured boot and remote attestation
- Flexible at Scale: Runs VMs, containers, Kubernetes, and NFVs side by side
- Hardware Neutral: Supports 75+ hardware types, from small gateways to powerful industrial servers
Why ZEDEDA’s EVE-OS Foundation is Built for Your Edge
EVE-OS goes beyond a traditional OS, delivering the core capabilities enterprises need to securely scale edge computing without compromise. With EVE-OS at the foundation of ZEDEDA, you can:
Virtualize Everything
Expose CPU, GPU, FPGA, and networking resources to applications with complete isolation.
Run Any Workload
Deploy modern containerized apps, legacy VMs, or full Kubernetes distributions.
Connect Anywhere
Operates reliably over wired, LTE, or Wi-Fi networks—even behind proxies, NATs, or firewalls, and continues on the last-known state if connectivity is lost, syncing when back online.
Future-Proof Foundation
EVE evolves publicly within the LF Edge ecosystem, supporting the latest edge innovation without vendor lock-in.
Built-In Security You Can Trust
EVE-OS implements a layered Zero Trust framework to secure every edge node:
- Measured boot and remote attestation validate system integrity.
- TPM-sealed identities ensure nodes cannot be cloned or spoofed.
- No inbound access required: EVE-OS exposes zero inbound ports, initiating all communication outbound to eliminate open firewall rules and block control-plane-originated attacks.
- All data is encrypted at rest and in flight (TLS).
- I/O isolation prevents tampering through physical ports.
- Cryptographically signed updates and dual partitions guarantee safe rollbacks.
Why EVE-OS Matters
Without a secure, flexible OS at the edge, distributed operations can’t scale. EVE-OS provides the trusted substrate that makes modern edge orchestration possible, giving you workload freedom, security assurance, and operational consistency wherever your edge strategy takes you.