-
Notifications
You must be signed in to change notification settings - Fork 41
Expand file tree
/
Copy pathContainerfile.qemu-runtime
More file actions
35 lines (32 loc) · 1.4 KB
/
Copy pathContainerfile.qemu-runtime
File metadata and controls
35 lines (32 loc) · 1.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
# QEMU runtime container for ExporterSet virtual targets.
# Provides QEMU tools for running virtual machines as part of
# the sidecar pattern (paired with the jumpstarter exporter).
#
# The exporter init container copies jumpstarter-exec to /shared/ before
# this container starts. jumpstarter-exec runs in serve mode, accepting
# remote command execution requests over a Unix socket.
#
# jumpstarter-exec emits JEP-0013-style JSON logs to stderr by default.
# Persistent correlation fields (exporter, namespace, component, …) come from
# JUMPSTARTER_EXEC_LOG_FIELDS / --log-field (injected by the provisioner).
# Set JUMPSTARTER_EXEC_DEBUG=1 (or pass --debug) to also log I/O
# previews for stdin/stdout/stderr of executed commands.
#
# Uses Fedora as the base image because QEMU packages are not
# available in UBI-minimal repositories.
FROM registry.fedoraproject.org/fedora-minimal:44
RUN dnf install --setopt=install_weak_deps=False -y \
qemu-img \
qemu-kvm \
qemu-system-aarch64 \
edk2-ovmf \
edk2-aarch64 \
procps-ng \
virtiofsd && \
dnf clean all
# Default image USER is non-root; ExporterSet QEMU pods override target-runtime
# to runAsUser 0 via Pod securityContext so QEMU can access devices and shared
# volume paths owned by the exporter container.
USER 65532:65532
ENTRYPOINT ["/shared/jumpstarter-exec"]
CMD ["serve", "--socket", "/shared/launcher.sock"]