mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-07-25 14:18:54 +00:00
Disable filesystem sharing for the non-confidential NVIDIA runtime-rs handler and use the EROFS snapshotter as its Kubernetes image-layer transport. This moves the runtime class toward a guest-owned storage model instead of relying on virtio-fs for container image layers and writable cache volumes. Configure kata-deploy's NVIDIA GPU values to install EROFS and select it for the qemu-nvidia-gpu-runtime-rs Kubernetes handler. Use memory-backed writable layers and dm-verity for lower-layer integrity. Adjust the NVIDIA GPU Kubernetes CI matrix so the non-confidential runtime-rs job exercises EROFS, while the Go and TEE jobs keep their existing snapshotter choices. Keep the Docker smoke test path on virtio-fs. The EROFS setup is targeted at the Kubernetes runtime-rs handler, where containerd can use the EROFS snapshotter for image layers. Adjust the runtime-rs NIM test selection and manifests closer to the TEE case, where filesystem sharing is already disabled and cache storage is guest-owned and ephemeral. Signed-off-by: Manuel Huber <manuelh@nvidia.com> Assisted-by: OpenAI Codex <codex@openai.com>
Kata Containers packaging
Introduction
Kata Containers currently supports packages for many distributions. Tooling to aid in creating these packages are contained within this repository.
Build in a container
Kata build artifacts are available within a container image, created by a
Dockerfile. Reference DaemonSets are provided in
kata-deploy, which make installation of Kata Containers in a
running Kubernetes Cluster very straightforward.
Build static binaries
See the static build documentation.
Build Kata Containers Kernel
Build QEMU
Create a Kata Containers release
See the release documentation.
Packaging scripts
See the scripts documentation.
Credits
Kata Containers packaging uses packagecloud for package hosting.