Installation

September 9, 2026 · View on GitHub

The Quickstart walks through an install with a verification step after each stage, ending with a pod running on exclusive CPUs. This page is the reference: compatibility, runtime setup, security, uninstall, and migration.

Compatibility

RequirementMinimum
Kubernetes1.34 (DRA resource.k8s.io/v1 is GA and enabled by default)
Container runtimecontainerd 2.0 or CRI-O 1.30 (NRI and CDI enabled by default)
KubeletCPUManager disabled: cpuManagerPolicy: none — see Configuration

Optional features need additional cluster feature gates:

FeatureKubernetes feature gate
grouped device mode (the default) on Kubernetes 1.34/1.35DRAConsumableCapacity (enabled by default from 1.36)
PCIe root attributes (--expose-pcie-roots)DRAListTypeAttributes

The driver is Linux-only and needs node-level privileges (host networking, and NRI socket, CDI directory, and kubelet plugin directory access) — see Security considerations.

Installing with Helm

If needed, create a kind cluster. We have one in the repo, if needed, that can be deployed as follows:

make kind-cluster

The recommended way to install the driver is via the provided Helm chart:

helm install dra-driver-cpu oci://registry.k8s.io/dra-driver-cpu/charts/dra-driver-cpu -n kube-system

See the Helm chart README for the full list of configuration options.

Besides the driver DaemonSet, the chart installs the cluster-scoped dra.cpu DeviceClass that workload claims reference — verify it with kubectl get deviceclass.

For environments with incomplete or synthetic sysfs topology, e.g. Docker Desktop for macOS see the sysfs overlay example. It demonstrates how to supply an overlay through driverConfig.sysfsOverlay, volume mounts, and volumes.

Container runtime setup

The driver relies on NRI (Node Resource Interface) to pin containers to their allocated CPUs, and on CDI (Container Device Interface) to inject the allocated cpuset into the container environment.

Minimum Runtime Requirements

Both NRI and CDI are enabled by default in modern container runtimes:

RuntimeNRI enabled by defaultCDI enabled by default
containerd2.0+2.0+
CRI-O1.30+always

Both runtimes also ship with the following CDI spec directories configured by default:

cdi_spec_dirs = ["/etc/cdi", "/var/run/cdi"]

No manual runtime configuration is needed if you are running one of the versions above or newer.

Manual Configuration for Older Runtimes

If you are running an older version of containerd (pre-2.0), you need to manually enable CDI and NRI in the containerd configuration (typically /etc/containerd/config.toml) and restart containerd.

Enable CDI:

[plugins."io.containerd.grpc.v1.cri"]
  enable_cdi = true
  cdi_spec_dirs = ["/etc/cdi", "/var/run/cdi"]

Enable NRI:

[plugins."io.containerd.nri.v1.nri"]
  disable = false
  disable_connections = false
  plugin_config_path = "/etc/nri/conf.d"
  plugin_path = "/opt/nri/plugins"
  plugin_registration_timeout = "5s"
  plugin_request_timeout = "5s"
  socket_path = "/var/run/nri/nri.sock"

After editing the config, restart containerd:

systemctl restart containerd

Security considerations

The driver needs node-level privileges: hostNetwork: true, and hostPath mounts for the NRI socket (/var/run/nri), the CDI spec directory (/var/run/cdi), and the kubelet plugin directories.

Upgrading (generic instructions)

Upgrade with Helm:

helm upgrade dra-driver-cpu oci://registry.k8s.io/dra-driver-cpu/charts/dra-driver-cpu -n kube-system

Uninstalling

helm uninstall dra-driver-cpu -n kube-system

Pods that are running keep their current cpusets, but nothing manages pinning or the shared pool anymore; delete or reschedule claim-bearing pods afterwards.

Installation via rendered manifest (deprecated)

Deprecated: Manifest-based installation is deprecated in favor of the Helm chart and will be removed in a future release. New users should use the Helm-based installation above.

make manifests
kubectl apply -f dist/helm-manifest.yaml