mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-07-25 14:18:54 +00:00
guest-components' coco-extension-image workflow now publishes two artefacts from the same assembled rootfs, and kata consumes each on the matching path: * Monolithic confidential rootfs (Go runtime): the scratch OCI container image from the "Publish OCI container image" step (ghcr.io/confidential-containers/guest-components/coco-extension). install_coco_guest_components() resolves the per-arch manifest digest, verifies provenance, and exports the filesystem into kata-static-coco-guest-components.tar.zst (binaries, cryptsetup, pause bundle, ocicrypt config). This replaces the local guest-components compile and removes the separate pause-image dependency from confidential rootfs targets. * Composable extension (runtime-rs): the EROFS + dm-verity disk image from the "Publish disk image with ORAS" step (ghcr.io/confidential-containers/guest-components/coco-extension-disk). install_image_coco_extension() resolves the per-arch digest, verifies provenance, and oras-pulls that exact digest into kata-static. Both paths pin the guest-components revision under .externals.coco-guest-components in versions.yaml (version, container_image, and extension_image must stay in sync). Provenance verification uses gh attestation verify --bundle-from-oci and fails the build by default (VERIFY_COCO_EXTENSION_PROVENANCE=no to bypass; skipped on s390x where gh has no binary). The build container installs the GitHub CLI and forwards GITHUB_TOKEN from the runner into the container. Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com> Assisted-by: Cursor <cursoragent@cursor.com>
Documentation
The Kata Containers documentation repository hosts overall system documentation, with information common to multiple components.
For details of the other Kata Containers repositories, see the repository summary.
Getting Started
- Quick Start Guide: Understand the basics and run your first Kata workload in minutes
- Installation guide: Install and run Kata Containers with Docker or Kubernetes
Tracing
See the tracing documentation.
More User Guides
- Upgrading: how to upgrade from Clear Containers and runV to Kata Containers and how to upgrade an existing Kata Containers system to the latest version.
- Limitations: differences and limitations compared with the default Docker runtime,
runc.
How-to guides
See the how-to documentation.
Kata Use-Cases
- GPU Passthrough with Kata
- SR-IOV with Kata
- Intel QAT with Kata
- SPDK vhost-user with Kata
- Intel SGX with Kata
- IBM Crypto Express passthrough with Confidential Containers
Developer Guide
Documents that help to understand and contribute to Kata Containers.
Design and Implementations
- Kata Containers Architecture: Architectural overview of Kata Containers
- Kata Containers CI: Kata Containers CI document
- Kata Containers E2E Flow: The entire end-to-end flow of Kata Containers
- Kata Containers design: More Kata Containers design documents
- Kata Containers threat model: Kata Containers threat model
How to Contribute
- Developer Guide: Setup the Kata Containers developing environments
- How to contribute to Kata Containers
- Code of Conduct
- How to submit a blog post
Help Writing a Code PR
Help Writing Unit Tests
Help Improving the Documents
Code Licensing
- Licensing: About the licensing strategy of Kata Containers.
The Release Process
Presentations
Website Changes
If you have a suggestion for how we can improve the website, please raise an issue (or a PR) on the repository that holds the source for the website.