Files
kata-containers/tools/osbuilder/rootfs-builder/devkit/Dockerfile.in
Fabiano Fidêncio 5b1ac36626 packaging: add generic devkit debug guest extension image
Add a self-contained "devkit" guest extension: a minimal Ubuntu (glibc +
busybox + apt) rootfs with common debug tools prebaked (strace, ltrace,
iproute2, procps, lsof, tcpdump, pciutils, util-linux, ...), built as a
measured erofs+dm-verity image mounted at /run/kata-extensions/devkit.

The production guest rootfs is minimal (and, for some bases, shell-less), so
the agent debug console has no rich interactive shell. Rather than rebuilding
the whole rootfs with debug tooling, this optional extension can be
cold-plugged alongside any base image. At runtime the guest helper scripts
overlay a writable tmpfs on the read-only extension and chroot in, so apt and
every tool run natively against a normal root filesystem; `apt install <pkg>`
inside the debug shell pulls anything else into the overlay on demand.

busybox-static (/usr/bin/busybox.static) bootstraps the overlay/chroot from the
shell-less base (the guest's dynamic loader is not present there yet); it is
installed at a dedicated path so it never clobbers the extension's own busybox
or /bin/sh, which are needed unclobbered inside the chroot.

The rootfs is built through osbuilder (rootfs.sh, with a ROOTFS_ONLY mode that
skips the agent/systemd setup) using mmdebstrap, the same tool the base guest
rootfs uses, so the devkit needs no bespoke chroot or docker-export logic. The
resulting tree is handed to image_builder.sh (mirroring the CoCo extension): it
ships no kata-agent, kernel or driver userspace.

No runtime wiring is added here; that follows in later commits. Nothing
consumes the image yet.

Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>
Assisted-by: Cursor <cursoragent@cursor.com>
2026-07-23 19:05:15 +02:00

20 lines
572 B
Docker

# Copyright (c) Kata Containers Community
#
# SPDX-License-Identifier: Apache-2.0
ARG IMAGE_REGISTRY=docker.io
FROM ${IMAGE_REGISTRY}/ubuntu:@OS_VERSION@
@SET_PROXY@
# mmdebstrap builds the devkit rootfs; the extension ships no agent, so none of
# the language toolchains the guest rootfs builder carries are needed here.
# hadolint ignore=DL3009
RUN apt-get update && \
DEBIAN_FRONTEND=noninteractive \
apt-get --no-install-recommends -y install \
ca-certificates \
file \
mmdebstrap \
zstd && \
apt-get clean && rm -rf /var/lib/apt/lists/*