Skip to content

feat: integrate the Kata Containers runtime#7

Merged
tianyuzhou95 merged 1 commit into
inclusionAI:mainfrom
tianyuzhou95:albert/kata
Jul 25, 2026
Merged

feat: integrate the Kata Containers runtime#7
tianyuzhou95 merged 1 commit into
inclusionAI:mainfrom
tianyuzhou95:albert/kata

Conversation

@tianyuzhou95

Copy link
Copy Markdown
Collaborator

What does this PR do?

This PR adds Kata Containers 4.0 as an optional AKernel sandbox runtime while keeping gVisor runsc as the default.

The all-in-one image packages the runtime-rs shim, Dragonball configuration and guest artifacts, and sandbox logger. Standalone, Helm, Alibaba Cloud, and Huawei Cloud deployments declare Kata as an optional runtime.

During node initialization, sandboxd validates the Kata components and /dev/kvm. A node without usable KVM remains ready and advertises only runsc. The Python SDK can request Kata with Sandbox(runtime="kata") and supports the default local rootfs, OCI images, and S3-backed EROFS images.

Testing

Verified the all-in-one image build, Python SDK unit tests, runsc and Kata integration tests and examples, concurrent pressure tests, and post-test resource cleanup.

Package the pinned Kata Containers 4.0 runtime-rs shim, Dragonball guest
kernel, guest image, and license in the all-in-one image. Enable the
optional Kata adapter in standalone and cloud deployment configurations
while keeping gVisor available on nodes without KVM.

Allow SDK callers to select the kata runtime and provide the default,
OCI, or S3-backed rootfs expected by the virtual machine. Make the SDK
integration and pressure suites runtime-selectable so runsc and Kata use
the same regression path.

Update the sandboxd submodule to the refactored implementation validated
by the standalone end-to-end tests.

Signed-off-by: Tianyu Zhou <albert.zty@antgroup.com>
@tianyuzhou95
tianyuzhou95 merged commit 29982af into inclusionAI:main Jul 25, 2026
5 checks passed
@tianyuzhou95
tianyuzhou95 deleted the albert/kata branch July 25, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant