mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-07-26 15:55:24 +00:00
Add a self-contained "devkit" guest extension: a minimal Alpine (musl + busybox + apk) rootfs with common debug tools prebaked (strace, ltrace, iproute2, procps, lsof, tcpdump, pciutils, util-linux, ...), built as a measured erofs+dm-verity image mounted at /run/kata-extensions/devkit. The production guest rootfs is minimal (and, for some bases, shell-less), so the agent debug console has no rich interactive shell. Rather than rebuilding the whole rootfs with debug tooling, this optional extension can be cold-plugged alongside any base image. At runtime the guest helper scripts overlay a writable tmpfs on the read-only extension and chroot in, so apk and every tool run natively against a normal root filesystem; `devkit-apk add <pkg>` (or plain `apk add` inside the debug shell) installs anything else into the overlay. Alpine's own busybox-static (/bin/busybox.static) bootstraps the overlay/chroot from the shell-less base (the dynamic musl loader is not present there yet); it is installed at a dedicated path so it never clobbers Alpine's /bin/busybox or /bin/sh, which are needed unclobbered inside the chroot. The image is assembled directly and handed to image_builder.sh (mirroring the CoCo extension), never going through rootfs.sh: it ships no kata-agent, kernel or driver userspace. No runtime wiring is added here; that follows in later commits. Nothing consumes the image yet. Signed-off-by: Fabiano Fidêncio <ffidencio@nvidia.com> Assisted-by: Cursor <cursoragent@cursor.com>