Files
Fabiano Fidêncio cd75c2fac5 build: consume guest-components CoCo artefacts instead of building locally
guest-components' coco-extension-image workflow now publishes two
artefacts from the same assembled rootfs, and kata consumes each on the
matching path:

* Monolithic confidential rootfs (Go runtime): the scratch OCI container
  image from the "Publish OCI container image" step
  (ghcr.io/confidential-containers/guest-components/coco-extension).
  install_coco_guest_components() resolves the per-arch manifest digest,
  verifies provenance, and exports the filesystem into
  kata-static-coco-guest-components.tar.zst (binaries, cryptsetup, pause
  bundle, ocicrypt config). This replaces the local guest-components
  compile and removes the separate pause-image dependency from
  confidential rootfs targets.

* Composable extension (runtime-rs): the EROFS + dm-verity disk image
  from the "Publish disk image with ORAS" step
  (ghcr.io/confidential-containers/guest-components/coco-extension-disk).
  install_image_coco_extension() resolves the per-arch digest, verifies
  provenance, and oras-pulls that exact digest into kata-static.

Both paths pin the guest-components revision under
.externals.coco-guest-components in versions.yaml (version,
container_image, and extension_image must stay in sync). Provenance
verification uses gh attestation verify --bundle-from-oci and fails the
build by default (VERIFY_COCO_EXTENSION_PROVENANCE=no to bypass; skipped
on s390x where gh has no binary). The build container installs the GitHub
CLI and forwards GITHUB_TOKEN from the runner into the container.

Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>
Assisted-by: Cursor <cursoragent@cursor.com>
2026-07-24 10:06:42 +03:00
..
2026-01-12 15:48:44 +01:00
2026-06-11 22:01:26 +02:00

Kata Containers packaging

Introduction

Kata Containers currently supports packages for many distributions. Tooling to aid in creating these packages are contained within this repository.

Build in a container

Kata build artifacts are available within a container image, created by a Dockerfile. Reference DaemonSets are provided in kata-deploy, which make installation of Kata Containers in a running Kubernetes Cluster very straightforward.

Build static binaries

See the static build documentation.

Build Kata Containers Kernel

See the kernel documentation.

Build QEMU

See the QEMU documentation.

Create a Kata Containers release

See the release documentation.

Packaging scripts

See the scripts documentation.

Credits

Kata Containers packaging uses packagecloud for package hosting.