Using UEFI mode for virtual machines¶
You can boot a virtual machine (VM) in Unified Extensible Firmware Interface (UEFI) mode for faster boot times, the ability to boot to larger disks, and added security features.
About UEFI mode for virtual machines¶
Unified Extensible Firmware Interface (UEFI), like legacy BIOS, initializes hardware components and operating system image files when a computer starts. UEFI supports more modern features and customization options than BIOS, enabling faster boot times.
It stores all the information about initialization and startup in a file with a .efi extension, which is stored on a special partition called EFI System Partition (ESP). The ESP also contains the boot loader programs for the operating system that is installed on the computer.
Booting virtual machines in UEFI mode¶
You can configure a virtual machine to boot in UEFI mode by editing the VirtualMachine manifest.
Prerequisites
- Install the OpenShift CLI (
oc).
Procedure
-
To boot a virtual machine (VM) in UEFI mode with secure boot active, edit or create a
VirtualMachinemanifest file. Use thespec.firmware.bootloaderstanza to configure UEFI mode:apiversion: kubevirt.io/v1 kind: VirtualMachine metadata: labels: special: vm-secureboot name: vm-secureboot spec: template: metadata: labels: special: vm-secureboot spec: domain: devices: disks: - disk: bus: virtio name: containerdisk features: acpi: {} smm: enabled: true firmware: bootloader: efi: secureBoot: true # ...- You must set
spec.template.spec.domain.features.ssm.enabledto have a value oftrue. - If
spec.template.spec.domain.firmware.bootloader.efi.secureBootis set totrue, then UEFI mode is required. However, you can enable UEFI mode without using Secure Boot.
- You must set
-
Apply the manifest to your cluster by running the following command:
Configuring VMs with persistent EFI¶
You can configure a VM to have EFI persistence enabled by editing its manifest file.
Procedure
-
Edit the VM manifest file and save to apply settings.