mirror of
https://github.com/containerd/containerd.git
synced 2026-08-09 09:33:06 +00:00
docs: reflow the erofs tar index mode section
Wrap the four long paragraphs at 80 columns to match the rest of the file. No text changes. Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
This commit is contained in:
@@ -329,16 +329,30 @@ with or without the EROFS differ.
|
||||
|
||||
## Tar Index Mode
|
||||
|
||||
The EROFS differ also supports a "tar index" mode that offers a unique approach to handling OCI image layers:
|
||||
The EROFS differ also supports a "tar index" mode that offers a unique approach
|
||||
to handling OCI image layers:
|
||||
|
||||
Instead of extracting the entire tar archive to create an EROFS filesystem, the tar index mode:
|
||||
Instead of extracting the entire tar archive to create an EROFS filesystem, the
|
||||
tar index mode:
|
||||
1. Generates a tar index for the tar content
|
||||
2. Appends the original tar content to the index
|
||||
3. Creates a combined file: `[Tar index][Original tar content]`
|
||||
|
||||
The tar index can be stored in a registry alongside image layers, allowing nodes to fetch it directly when needed. Typically, the tar index is much smaller than a full EROFS blob, making it more efficient to store and transfer. If the tar index is not available in the registry, it can be generated on the node as a fallback. When integrating with dm-verity, the registry can also store the dm-verity Merkle tree and root hash signature together with the tar index, enabling nodes to retrieve all necessary artifacts without redundant computation.
|
||||
The tar index can be stored in a registry alongside image layers, allowing nodes
|
||||
to fetch it directly when needed. Typically, the tar index is much smaller than
|
||||
a full EROFS blob, making it more efficient to store and transfer. If the tar
|
||||
index is not available in the registry, it can be generated on the node as a
|
||||
fallback. When integrating with dm-verity, the registry can also store the
|
||||
dm-verity Merkle tree and root hash signature together with the tar index,
|
||||
enabling nodes to retrieve all necessary artifacts without redundant
|
||||
computation.
|
||||
|
||||
In addition, we have a tar diffID for each layer according to the OCI image spec, so we don't need to reinvent a new way to verify the image layer content for confidential containers but just calculate the sha256 of the original tar data (because erofs could just reuse the tar data with 512-byte fs block size and build a minimal index for direct mounting of tar) out of the tar index mode in the guest and compare it with each diffID.
|
||||
In addition, we have a tar diffID for each layer according to the OCI image
|
||||
spec, so we don't need to reinvent a new way to verify the image layer content
|
||||
for confidential containers but just calculate the sha256 of the original tar
|
||||
data (because erofs could just reuse the tar data with 512-byte fs block size
|
||||
and build a minimal index for direct mounting of tar) out of the tar index mode
|
||||
in the guest and compare it with each diffID.
|
||||
|
||||
### Configuration
|
||||
|
||||
|
||||
Reference in New Issue
Block a user