Installation / Requirements and sizing

Requirements and sizing

What the host needs, and how to size the appliance for the environments you plan to run.

On this page
  1. The host
  2. Nested virtualization
  3. Sizing for environments
    1. The Content Hub check against your appliance
    2. Multi-device ranges
    3. Limits by edition
  4. Other things that take memory
  5. Growing the disk

Sizing an ONEP appliance means two numbers: what the appliance itself needs, and what each environment adds while it runs. The appliance's own share is modest and roughly fixed. An environment can need a few gigabytes for one small appliance, or much more for a multi-device range.

The host#

ItemMinimumRecommendedNotes
CPU4 vCPU4 to 8 vCPUIntel VT-x or AMD-V, with nested virtualization turned on for the appliance
Memory8 GB16 GBSmall environment (2 to 3 devices, one virtual machine, or a dozen routers and switches): 8 GB. Medium (4 to 8 devices, 3 or 4 virtual machines): 16 GB. Large (10 to 20 devices, 6 to 8 virtual machines): 32 GB. Security appliances follow their vendor's own numbers
Disk200 GB virtual disk, thin-provisionedRoom for your images and environmentsThe disk takes space on the host only as it fills. Large monitoring cards declare up to 200 GB
NetworkOne interfaceOne interfaceDHCP is fine. Environments need no network of their own
HypervisorProxmox VE, VMware Workstation, VirtualBoxInstall steps are given for all three. See Choose your format
BrowserA current Chromium-based browserNothing to install on your laptop

The appliance reports a missing nested virtualization on its console banner and in Settings › Status. See Troubleshooting.

Nested virtualization#

Virtual machine devices need hardware virtualization. When the appliance itself runs in a virtual machine, the hypervisor must pass hardware virtualization through to it. Turn it on before you start the appliance:

  • Proxmox VE: set the virtual machine's CPU type to host.
  • VMware Workstation: expose hardware-assisted virtualization (Intel VT-x/EPT or AMD-V/RVI) to the guest.
  • VirtualBox: tick Enable Nested VT-x/AMD-V under System › Processor.

Without it, virtual machine devices do not start, and the appliance says so: the console banner reads Virtual machines: not available until nested virtualization is enabled on your hypervisor, and Settings › Status shows the same on its Virtualization line. Routers and containers work without it.

Sizing for environments#

Every running device takes the CPU, memory and disk shown in its plan. Before you deploy, the Content Hub wizard shows a Resolved plan step with the vCPU, memory and disk of every device, and lets you override them. Size the appliance against that step.

The Content Hub check against your appliance#

For the HELK, Malcolm, Security Onion, Vulhub and PatrOWL cards, the Content Hub compares the card with the appliance before a deploy:

  • Memory refuses. If the appliance has too little memory, the card shows Needs N GB RAM in place of the Deploy button. N includes the memory the platform keeps for itself, rounded up to a common memory size.
  • Cores only warn. If the appliance has fewer cores than the card recommends, the card shows Runs slowly: N cores recommended. The deploy is still allowed.

Multi-device ranges#

Multi-device ranges are larger than a single appliance and need a bigger host. The Resolved plan step in the Content Hub wizard shows the CPU, memory and disk before you deploy. Which ranges you can deploy depends on your edition.

Limits by edition#

Editions limit how many devices run at once and how large a single device can be, among other things. Every number is in Limits per edition.

Other things that take memory#

  • Builds. The first deploy of a card builds it on your appliance, which uses CPU and memory while it runs. Run one heavy job at a time: a large range deploy and a card build at the same time compete for CPU.

Growing the disk#

Images and environments live on the appliance's disk, which is a 200 GB thin-provisioned disk. To give it more room, enlarge the virtual disk in your hypervisor. On its next boot the appliance grows its file system to use the new space automatically.

Something wrong or missing on this page? Write to hello@onep.io.