mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-03-18 02:32:26 +00:00
Building Kata components requires downloading tools like ORAS, cloud-hypervisor, nydus, jq, cosign, upx, and gh CLI from GitHub releases. Without authentication, these downloads can hit GitHub's rate limits causing build failures. This commit ensures GH_TOKEN is passed down to all build-related steps: GitHub Actions workflows: - build-kata-static-tarball-amd64.yaml - build-kata-static-tarball-arm64.yaml - build-kata-static-tarball-s390x.yaml - build-kata-static-tarball-ppc64le.yaml - build-kata-static-tarball-riscv64.yaml Docker build infrastructure: - kata-deploy-binaries-in-docker.sh: Pass GH_TOKEN to docker build and run - dockerbuild/Dockerfile: Accept GH_TOKEN as build arg - dockerbuild/install_oras.sh: Use GH_TOKEN for ORAS downloads Other scripts with GitHub downloads: - lib.sh: gh CLI download - ubuntu/Dockerfile.in: cosign download - kata-deploy/Dockerfile: jq and nydus-snapshotter downloads - nvidia_rootfs.sh: upx download - cloud-hypervisor/build-static-clh.sh: cloud-hypervisor binary download - nydus/build.sh: nydus binary download Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>