Kata 4.1.0 bundles virtiofsd 1.14.0 (required by Substrate). This simplifies the dev process on arm64 because it removes the need to build virtiofsd from source. Verified on an arm64 KVM host (Lima + kind). Fixes #1695 > It's a good idea to open an issue first for discussion. - [x] Tests pass - [x] Appropriate changes to documentation are included in the PR
Micro-VM runtime assets + counter demo (kind, fetch-not-bake)
The microvm runtime (cmd/ateom-microvm, kata + cloud-hypervisor) fetches its
toolchain at runtime — nothing kata-specific is baked into the worker image. ateom drives
the kata-agent directly (no kata shim, no containerd). Each actor container's rootfs is an
overlay of a read-only lower (the OCI image, served into the guest over virtio-fs by
virtiofsd) and a writable upper on a guest tmpfs, so virtiofsd is part of the asset
set. The asset set is four files:
cloud-hypervisor— the VMM binary (fetched from its release)virtiofsd— the virtio-fs daemon serving the RO lower (from kata-static)vmlinux— the guest kernel (from kata-static)rootfs.img— the guest rootfs image (from kata-static)
These helpers assemble the asset set for your node arch, stage it into the cluster's rustfs
S3 bucket, and the demo manifest's SandboxConfig points at it. When /dev/kvm is
available, hack/create-kind-cluster.sh mounts it into the node; atelet then advertises
it as a device, which is what places micro-VM workers there.
Tip
hack/run-microvm-demo.shautomates the full bring-up below (assets, control plane, demo apply) for kind OR GKE without editing committed files. The steps here are the manual equivalent.
Steps (run on a KVM-capable Linux host matching the node arch)
-
Assemble assets for your arch:
ARCH=arm64 hack/microvm-assets/assemble.sh -
Bring up the cluster + control plane:
hack/create-kind-cluster.sh # mounts /dev/kvm into the nodes hack/install-ate-kind.sh # control plane + rustfs (bucket: ate-snapshots) -
Stage assets into rustfs:
OUT="$PWD/microvm-assets-arm64" hack/microvm-assets/stage-to-rustfs.sh -
Apply the demo + drive it:
BUCKET_NAME=ate-snapshots SUBSTRATE_VERSION="$(git describe --tags --always --dirty)" envsubst < demos/counter/counter-microvm.yaml.tmpl | kubectl apply -f - # the pool pins workers to nodes labeled with this versionCreate an actor from
counter-microvm, hit the in-RAM counter to increment it, suspend (checkpoint), resume on a different worker pod, and confirm the count continues — proving the guest-memory snapshot round-tripped across pods.
Notes
assetsis single-arch (unlike runsc's amd64/arm64): stage assets matching the node arch.