Go to file
Fabiano Fidêncio 33e5ab1bf6
Merge pull request #2624 from andreabolognani/feature-selinux
makefile: Make SELinux support configurable
2020-04-17 15:04:04 +02:00
.ci Merge pull request #2452 from GabyCT/topic/skipvirtcontainers 2020-02-11 16:14:56 -06:00
.github github: Add issue template 2018-03-22 13:56:43 +00:00
arch AArch64: enable firecracker v0.21.1 on AArch64 2020-03-23 09:57:25 +08:00
cli devices: add vhost-user storage configuration 2020-03-11 21:18:29 -04:00
containerd-shim-v2 v2: Open log fifo with RDWR instead of WRONLY 2020-04-10 14:58:56 +08:00
data Merge pull request #1721 from devimc/topic/data/kataCollectSupportSnap 2019-05-24 15:38:42 +01:00
hack virtcontainers: Add SELinux support for running VM Confinement 2020-04-02 09:19:45 -04:00
netmon ipv6: Add support for ipv6 for netmon as well. 2020-01-28 16:31:31 -08:00
pkg Merge pull request #2561 from justin-he/scsi_async 2020-04-16 07:28:48 -05:00
protocols/cache factory: Make factory status can show status of VMCache server 2019-04-10 11:03:14 +08:00
vendor virtcontainers: Add SELinux support for running VM Confinement 2020-04-02 09:19:45 -04:00
virtcontainers clh: Boot from persistent memory device 2020-04-15 17:08:20 -07:00
.gitignore katautils: Use config paths set during the build 2020-04-15 13:40:02 +02:00
.gitmodules submodules: Remove cc-runtime and runv 2018-03-21 12:10:15 -07:00
.travis.yml versions: Update go to 1.13.9 2020-04-07 13:04:59 -05:00
CODE_OF_CONDUCT.md docs: Add missing standard docs 2018-02-09 14:45:14 +00:00
CODEOWNERS ci: Add a CODEOWNERS file for github ack checks 2019-01-30 11:23:25 +00:00
CONTRIBUTING.md docs: Add missing standard docs 2018-02-09 14:45:14 +00:00
golang.mk Makefile: Change "GOPATH not set" to "No GO command or GOPATH not set" 2019-03-01 22:47:37 +08:00
Gopkg.lock virtcontainers: Add SELinux support for running VM Confinement 2020-04-02 09:19:45 -04:00
Gopkg.toml virtcontainers: Add SELinux support for running VM Confinement 2020-04-02 09:19:45 -04:00
LICENSE Initial commit 2017-11-21 17:03:45 +08:00
Makefile makefile: Make SELinux support configurable 2020-04-17 12:03:22 +02:00
README.md README: logging: add shimv2 information 2020-03-10 16:01:47 +00:00
VERSION release: Kata Containers 1.11.0-alpha1 2020-03-16 12:39:48 +00:00
versions.yaml version: Update clh to master 2020-04-15 17:08:12 -07:00

Build Status Build Status Go Report Card GoDoc

Runtime

This repository contains the runtime for the Kata Containers project.

For details of the other Kata Containers repositories, see the repository summary.

Introduction

kata-runtime, referred to as "the runtime", is the Command-Line Interface (CLI) part of the Kata Containers runtime component. It leverages the virtcontainers package to provide a high-performance standards-compliant runtime that creates hardware-virtualized Linux containers running on Linux hosts.

The runtime is OCI-compatible, CRI-O-compatible, and Containerd-compatible, allowing it to work seamlessly with both Docker and Kubernetes respectively.

License

The code is licensed under an Apache 2.0 license.

See the license file for further details.

Platform support

Kata Containers currently works on systems supporting the following technologies:

  • Intel VT-x technology.
  • ARM Hyp mode (virtualization extension).
  • IBM Power Systems.
  • IBM Z mainframes.

Hardware requirements

The runtime has a built-in command to determine if your host system is capable of running and creating a Kata Container:

$ kata-runtime kata-check

Note:

  • By default, only a brief success / failure message is printed. If more details are needed, the --verbose flag can be used to display the list of all the checks performed.

  • root permission is needed to check if the system is capable of running Kata containers. In this case, additional checks are performed (e.g., if another incompatible hypervisor is running).

Download and install

Get it from the Snap Store

See the installation guides available for various operating systems.

Quick start for developers

See the developer guide.

Architecture overview

See the architecture overview for details on the Kata Containers design.

Configuration

The runtime uses a TOML format configuration file called configuration.toml. The file contains comments explaining all options.

Note:

The initial values in the configuration file provide a good default configuration. You may need to modify this file to optimise or tailor your system, or if you have specific requirements.

Since the runtime supports a stateless system, it checks for this configuration file in multiple locations, two of which are built in to the runtime. The default location is /usr/share/defaults/kata-containers/configuration.toml for a standard system. However, if /etc/kata-containers/configuration.toml exists, this takes priority.

The below command lists the full paths to the configuration files that the runtime attempts to load. The first path that exists will be used:

$ kata-runtime --kata-show-default-config-paths

Aside from the built-in locations, it is possible to specify the path to a custom configuration file using the --kata-config option:

$ kata-runtime --kata-config=/some/where/configuration.toml ...

The runtime will log the full path to the configuration file it is using. See the logging section for further details.

To see details of your systems runtime environment (including the location of the configuration file being used), run:

$ kata-runtime kata-env

Logging

For detailed information and analysis on obtaining logs for other system components, see the documentation for the kata-log-parser tool.

For runtime logs, see the following sections for the CRI-O and containerd shimv2 based runtimes.

Kata OCI

The Kata OCI runtime (including when used with CRI-O), provides --log= and --log-format= options. However, the runtime also always logs to the system log (syslog or journald).

To view runtime log output:

$ sudo journalctl -t kata-runtime

Kata containerd shimv2

The Kata containerd shimv2 runtime logs through containerd, and its logs will be sent to wherever the containerd logs are directed. However, the shimv2 runtime also always logs to the system log (syslog or journald) under the identifier name of kata.

To view the shimv2 runtime log output:

$ sudo journalctl -t kata

Debugging

See the debugging section of the developer guide.

Limitations

See the limitations file for further details.

Community

See the community repository.

Contact

See how to reach the community.

Further information

See the project table of contents and the documentation repository.

Additional packages

For details of the other packages contained in this repository, see the package documentation.