Files
Fabiano Fidêncio cd75c2fac5 build: consume guest-components CoCo artefacts instead of building locally
guest-components' coco-extension-image workflow now publishes two
artefacts from the same assembled rootfs, and kata consumes each on the
matching path:

* Monolithic confidential rootfs (Go runtime): the scratch OCI container
  image from the "Publish OCI container image" step
  (ghcr.io/confidential-containers/guest-components/coco-extension).
  install_coco_guest_components() resolves the per-arch manifest digest,
  verifies provenance, and exports the filesystem into
  kata-static-coco-guest-components.tar.zst (binaries, cryptsetup, pause
  bundle, ocicrypt config). This replaces the local guest-components
  compile and removes the separate pause-image dependency from
  confidential rootfs targets.

* Composable extension (runtime-rs): the EROFS + dm-verity disk image
  from the "Publish disk image with ORAS" step
  (ghcr.io/confidential-containers/guest-components/coco-extension-disk).
  install_image_coco_extension() resolves the per-arch digest, verifies
  provenance, and oras-pulls that exact digest into kata-static.

Both paths pin the guest-components revision under
.externals.coco-guest-components in versions.yaml (version,
container_image, and extension_image must stay in sync). Provenance
verification uses gh attestation verify --bundle-from-oci and fails the
build by default (VERIFY_COCO_EXTENSION_PROVENANCE=no to bypass; skipped
on s390x where gh has no binary). The build container installs the GitHub
CLI and forwards GITHUB_TOKEN from the runner into the container.

Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>
Assisted-by: Cursor <cursoragent@cursor.com>
2026-07-24 10:06:42 +03:00
..
2026-03-19 10:22:54 +00:00
2020-06-23 21:27:23 -07:00

Documentation

The Kata Containers documentation repository hosts overall system documentation, with information common to multiple components.

For details of the other Kata Containers repositories, see the repository summary.

Getting Started

Tracing

See the tracing documentation.

More User Guides

How-to guides

See the how-to documentation.

Kata Use-Cases

Developer Guide

Documents that help to understand and contribute to Kata Containers.

Design and Implementations

How to Contribute

Help Writing a Code PR

Help Writing Unit Tests

Help Improving the Documents

Code Licensing

  • Licensing: About the licensing strategy of Kata Containers.

The Release Process

Presentations

Website Changes

If you have a suggestion for how we can improve the website, please raise an issue (or a PR) on the repository that holds the source for the website.

Toolchain Guidance