Skip to content

feat: add a containerd config to enable EROFS snapshotter and referrer flag when IPE is enabled - #98

Draft
Dallas Delaney (dallasd1) wants to merge 1 commit into
aclmainfrom
dadelan/ipe-config-containerd-pr
Draft

Dallas Delaney (dallasd1) wants to merge 1 commit into
aclmainfrom
dadelan/ipe-config-containerd-pr

Conversation

@dallasd1

@dallasd1 Dallas Delaney (dallasd1) commented Oct 9, 2026 •

Copy link
Copy Markdown

Summary

Add a containerd config to enable EROFS snapshotter and referrer flag when IPE is enabled. This config change will only be triggered if IPE is in audit mode. When IPE is set, IPE's loader will run the acl-select-profile script to merge the base containerd config that AgentBaker or ACL sets with the EROFS config. None of the settings in the base config get overwritten.

This is a follow up PR for after the containerd2 patch enabling dmverity referrers is merged.

Change Log

  • sysext for containerd gets the erofs-utils package

Type of Change

  • Image build change (base image, sysexts, OEM images)
  • Package/SPEC update
  • CI/automation change
  • SDK/toolchain update
  • Configuration change
  • Documentation update
  • Bug fix

Does this affect the image build?

  • Yes
  • No

Associated Issues

Test Methodology

  • Test details: The tests in acl-pipelines pass, the AKS e2e tests all pass, local validation of non-IPE OverlayFS and IPE EROFS behavior was tested and with containerd configurations examined for expected values.

Merge Checklist

All applicable boxes should be checked before merging

  • Image builds successfully with this change (or image build is not affected)
  • Any updated packages/SPECs build successfully
  • Relevant kola tests pass
  • All package sources are available
  • Source files have up-to-date hashes/manifests
  • Documentation has been updated to match any changes
  • Ready to merge

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The documented enforcing-mode behavior contradicts the loader implementation and its tests.

1 open finding
What changed in this PR

Adds IPE-triggered EROFS configuration for containerd while preserving the selected base configuration.

Changes:

  • Adds EROFS tooling and containerd profile assets.
  • Installs the profile after IPE activation.
  • Adds runtime/offline validation and documentation.
File Description
build_library/​rpm/​sysext_mangle_containerd-flatcar.sh Installs EROFS profile assets.
build_library/​rpm/​dracut_install.sh Adds the profile to the IPE dracut module.
build_library/​rpm/​additional_files/​dracut-acl-ipe-load/​module-setup.sh Installs the profile into initramfs.
build_library/​rpm/​additional_files/​dracut-acl-ipe-load/​acl-ipe-load.sh Activates the containerd drop-in with IPE.
build_library/​rpm/​additional_files/​containerd2/​containerd-acl-select-profile Merges and validates containerd configurations.
build_library/​rpm/​additional_files/​containerd2/​containerd-acl-profile.conf Overrides containerd startup for EROFS.
build_library/​rpm/​additional_files/​containerd2/​containerd-acl-erofs.toml Configures EROFS snapshotting and referrers.
acl/​tests/​ipe/​run-ipe-audit-test.sh Validates the active containerd profile.
acl/​tests/​ipe/​offline/​test-ipe-loader-runtime.sh Tests profile installation by IPE mode.
acl/​sysexts.yaml Adds erofs-utils to the containerd sysext.
acl/​docs/​BUILD_RPM_IMAGE_README.md Documents IPE/containerd integration.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread acl/tests/ipe/offline/test-ipe-loader-runtime.sh

This branch was successfully deployed

1 active deployment
development — 2e9d785e Deployed Oct 9, 2026 by dallasd1 via Check if we need to update the SDK #110
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants