feat: integrate the Kata Containers runtime#7
Merged
Conversation
Package the pinned Kata Containers 4.0 runtime-rs shim, Dragonball guest kernel, guest image, and license in the all-in-one image. Enable the optional Kata adapter in standalone and cloud deployment configurations while keeping gVisor available on nodes without KVM. Allow SDK callers to select the kata runtime and provide the default, OCI, or S3-backed rootfs expected by the virtual machine. Make the SDK integration and pressure suites runtime-selectable so runsc and Kata use the same regression path. Update the sandboxd submodule to the refactored implementation validated by the standalone end-to-end tests. Signed-off-by: Tianyu Zhou <albert.zty@antgroup.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
This PR adds Kata Containers 4.0 as an optional AKernel sandbox runtime while keeping gVisor runsc as the default.
The all-in-one image packages the runtime-rs shim, Dragonball configuration and guest artifacts, and sandbox logger. Standalone, Helm, Alibaba Cloud, and Huawei Cloud deployments declare Kata as an optional runtime.
During node initialization, sandboxd validates the Kata components and
/dev/kvm. A node without usable KVM remains ready and advertises only runsc. The Python SDK can request Kata withSandbox(runtime="kata")and supports the default local rootfs, OCI images, and S3-backed EROFS images.Testing
Verified the all-in-one image build, Python SDK unit tests, runsc and Kata integration tests and examples, concurrent pressure tests, and post-test resource cleanup.