Files
kata-containers/tools/packaging
Zvonko Kaiser ed988cdb88 build(qemu): activate --without-default-devices with complete allowlist
The --without-default-devices flag was parked in a comment while the
per-architecture device allowlist was incomplete: the runtimes emit
devices that were missing from it, so a build with the flag active
produced a QEMU that failed at VM start rather than at build time.

Complete the allowlist with every device the Go runtime and runtime-rs
can emit:

- VIRTIO_SCSI    virtio-scsi + scsi-hd (block_device_driver=virtio-scsi)
- VHOST_USER_BLK / VHOST_USER_SCSI  vhost-user block backends
- NVDIMM         DAX rootfs image (x86_64, aarch64, ppc64le)
- PCIE_PORT      pcie-root-port: hot-plug slots and root-port topology
- XIO3130        x3130-upstream/xio3130-downstream: switch-port topology
- PCI_BRIDGE     pci-bridge: bridge-port topology
- PCIE_PCI_BRIDGE pcie-pci-bridge
- PXB            pxb-pcie on x86_64 (NUMA-pinned GPU root complexes);
                 aarch64 already carried it as a CXL dependency
- PVPANIC_ISA    pvpanic guest kernel panic reporting (x86_64)

The allowlist is split into transport-independent device models
(_COMMON_DEVS, all architectures) and PCI transport + PCIe slot
topology (_PCIE_DEVS, x86_64/aarch64; ppc64le takes the conventional
PCI subset since pSeries PHBs have no PCIe ports; s390x is pure CCW).

A post-build verify_devices check runs `qemu-system-* -device help`
and fails the build if any required device is missing, so allowlist
gaps surface at build time, never at VM start.  The check is skipped
when cross-compiling since the binary cannot run on the build host.

Signed-off-by: Zvonko Kaiser <zkaiser@nvidia.com>
Assisted-by: Claude <noreply@anthropic.com>
2026-07-21 14:57:47 +00:00
..
2026-01-12 15:48:44 +01:00
2026-06-11 22:01:26 +02:00

Kata Containers packaging

Introduction

Kata Containers currently supports packages for many distributions. Tooling to aid in creating these packages are contained within this repository.

Build in a container

Kata build artifacts are available within a container image, created by a Dockerfile. Reference DaemonSets are provided in kata-deploy, which make installation of Kata Containers in a running Kubernetes Cluster very straightforward.

Build static binaries

See the static build documentation.

Build Kata Containers Kernel

See the kernel documentation.

Build QEMU

See the QEMU documentation.

Create a Kata Containers release

See the release documentation.

Packaging scripts

See the scripts documentation.

Credits

Kata Containers packaging uses packagecloud for package hosting.