mirror of
https://github.com/kata-containers/kata-containers.git
synced 2026-07-25 14:18:54 +00:00
Disable filesystem sharing for the non-confidential NVIDIA runtime-rs handler and use the EROFS snapshotter as its Kubernetes image-layer transport. This moves the runtime class toward a guest-owned storage model instead of relying on virtio-fs for container image layers and writable cache volumes. Configure kata-deploy's NVIDIA GPU values to install EROFS and select it for the qemu-nvidia-gpu-runtime-rs Kubernetes handler. Use memory-backed writable layers and dm-verity for lower-layer integrity. Adjust the NVIDIA GPU Kubernetes CI matrix so the non-confidential runtime-rs job exercises EROFS, while the Go and TEE jobs keep their existing snapshotter choices. Keep the Docker smoke test path on virtio-fs. The EROFS setup is targeted at the Kubernetes runtime-rs handler, where containerd can use the EROFS snapshotter for image layers. Adjust the runtime-rs NIM test selection and manifests closer to the TEE case, where filesystem sharing is already disabled and cache storage is guest-owned and ephemeral. Signed-off-by: Manuel Huber <manuelh@nvidia.com> Assisted-by: OpenAI Codex <codex@openai.com>
Kata Containers Tests
This directory contains various types of tests for testing the Kata Containers repository.
Test Content
We provide several tests to ensure Kata-Containers run on different scenarios and with different container managers.
- Integration tests to ensure compatibility with:
- Stability tests
- Functional
GitHub Actions
Kata Containers uses GitHub Actions in the Kata Containers repository.