Files
Huy Pham 92a84388b4 microvm: bump kata assets to 4.1.0 (#1708)
Kata 4.1.0 bundles virtiofsd 1.14.0 (required by Substrate). This
simplifies the dev process on arm64 because it removes the need to build
virtiofsd from source.

Verified on an arm64 KVM host (Lima + kind).

Fixes #1695

> It's a good idea to open an issue first for discussion.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR
2026-09-22 16:07:12 +00:00
..

Micro-VM runtime assets + counter demo (kind, fetch-not-bake)

The microvm runtime (cmd/ateom-microvm, kata + cloud-hypervisor) fetches its toolchain at runtime — nothing kata-specific is baked into the worker image. ateom drives the kata-agent directly (no kata shim, no containerd). Each actor container's rootfs is an overlay of a read-only lower (the OCI image, served into the guest over virtio-fs by virtiofsd) and a writable upper on a guest tmpfs, so virtiofsd is part of the asset set. The asset set is four files:

  • cloud-hypervisor — the VMM binary (fetched from its release)
  • virtiofsd — the virtio-fs daemon serving the RO lower (from kata-static)
  • vmlinux — the guest kernel (from kata-static)
  • rootfs.img — the guest rootfs image (from kata-static)

These helpers assemble the asset set for your node arch, stage it into the cluster's rustfs S3 bucket, and the demo manifest's SandboxConfig points at it. When /dev/kvm is available, hack/create-kind-cluster.sh mounts it into the node; atelet then advertises it as a device, which is what places micro-VM workers there.

Tip

hack/run-microvm-demo.sh automates the full bring-up below (assets, control plane, demo apply) for kind OR GKE without editing committed files. The steps here are the manual equivalent.

Steps (run on a KVM-capable Linux host matching the node arch)

  1. Assemble assets for your arch:

    ARCH=arm64 hack/microvm-assets/assemble.sh
    
  2. Bring up the cluster + control plane:

    hack/create-kind-cluster.sh        # mounts /dev/kvm into the nodes
    hack/install-ate-kind.sh           # control plane + rustfs (bucket: ate-snapshots)
    
  3. Stage assets into rustfs:

    OUT="$PWD/microvm-assets-arm64" hack/microvm-assets/stage-to-rustfs.sh
    
  4. Apply the demo + drive it:

    BUCKET_NAME=ate-snapshots SUBSTRATE_VERSION="$(git describe --tags --always --dirty)" envsubst < demos/counter/counter-microvm.yaml.tmpl | kubectl apply -f -   # the pool pins workers to nodes labeled with this version
    

    Create an actor from counter-microvm, hit the in-RAM counter to increment it, suspend (checkpoint), resume on a different worker pod, and confirm the count continues — proving the guest-memory snapshot round-tripped across pods.

Notes

  • assets is single-arch (unlike runsc's amd64/arm64): stage assets matching the node arch.