Files
kata-containers/tools/packaging/scripts
Fabiano Fidêncio 0a3e5f5fcf workflows: Use GH_TOKEN to avoid GitHub rate limits
Building Kata components requires downloading tools like ORAS, cloud-hypervisor,
nydus, jq, cosign, upx, and gh CLI from GitHub releases. Without authentication,
these downloads can hit GitHub's rate limits causing build failures.

This commit ensures GH_TOKEN is passed down to all build-related steps:

GitHub Actions workflows:
- build-kata-static-tarball-amd64.yaml
- build-kata-static-tarball-arm64.yaml
- build-kata-static-tarball-s390x.yaml
- build-kata-static-tarball-ppc64le.yaml
- build-kata-static-tarball-riscv64.yaml

Docker build infrastructure:
- kata-deploy-binaries-in-docker.sh: Pass GH_TOKEN to docker build and run
- dockerbuild/Dockerfile: Accept GH_TOKEN as build arg
- dockerbuild/install_oras.sh: Use GH_TOKEN for ORAS downloads

Other scripts with GitHub downloads:
- lib.sh: gh CLI download
- ubuntu/Dockerfile.in: cosign download
- kata-deploy/Dockerfile: jq and nydus-snapshotter downloads
- nvidia_rootfs.sh: upx download
- cloud-hypervisor/build-static-clh.sh: cloud-hypervisor binary download
- nydus/build.sh: nydus binary download

Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com>
2025-12-11 14:43:20 +01:00
..

Packaging scripts

This directory contains useful packaging scripts.

configure-hypervisor.sh

This script generates the official set of QEMU-based hypervisor build configuration options. All repositories that need to build a hypervisor from source MUST use this script to ensure the hypervisor is built in a known way since using a different set of options can impact many areas including performance, memory footprint and security.

Example usage:

  $ configure-hypervisor.sh qemu