1"use strict";(self.webpackChunkig_website=self.webpackChunkig_website||[]).push([[21633],{66751:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>d,contentTitle:()=>c,default:()=>h,frontMatter:()=>r,metadata:()=>i,toc:()=>o});const i=JSON.parse('{"id":"spec/oci","title":"Gadgets as OCI artifacts","description":"Reference documentation for the format of a gadget OCI artifact","source":"@site/versioned_docs/version-v0.54.1/spec/oci.md","sourceDirName":"spec","slug":"/spec/oci","permalink":"/docs/v0.54.1/spec/oci","draft":false,"unlisted":false,"editUrl":"https://github.com/inspektor-gadget/inspektor-gadget/edit/main/versioned_docs/version-v0.54.1/spec/oci.md","tags":[],"version":"v0.54.1","sidebarPosition":20,"frontMatter":{"title":"Gadgets as OCI artifacts","sidebar_position":20,"description":"Reference documentation for the format of a gadget OCI artifact"},"sidebar":"mainSidebar","previous":{"title":"UidGidResolver","permalink":"/docs/v0.54.1/spec/operators/uidgidresolver"}}');var a=n(74848),s=n(28453);const r={title:"Gadgets as OCI artifacts",sidebar_position:20,description:"Reference documentation for the format of a gadget OCI artifact"},c=void 0,d={},o=[{value:"Specifications",id:"specifications",level:2},{value:"Architectures",id:"architectures",level:2},{value:"ArtifactType",id:"artifacttype",level:2},{value:"Gadget metadata",id:"gadget-metadata",level:2},{value:"Image layers and media types",id:"image-layers-and-media-types",level:2},{value:"The ebpf layer",id:"the-ebpf-layer",level:3},{value:"The wasm layer",id:"the-wasm-layer",level:3},{value:"The btfgen layer",id:"the-btfgen-layer",level:3},{value:"Image annotations",id:"image-annotations",level:2}];function l(e){const t={a:"a",code:"code",h2:"h2",h3:"h3",li:"li",p:"p",ul:"ul",...(0,s.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(t.p,{children:"Intro TODO"}),"\n",(0,a.jsx)(t.h2,{id:"specifications",children:"Specifications"}),"\n",(0,a.jsxs)(t.p,{children:["The ",(0,a.jsx)(t.a,{href:"https://opencontainers.org/",children:"Open Container Initiative"})," defines the ",(0,a.jsx)(t.a,{href:"https://github.com/opencontainers/image-spec/blob/main/spec.md",children:"Image\nFormat\nSpecification"}),".\nThis specification was initially defined for container images but it is\nextended to store other artifacts, see ",(0,a.jsx)(t.a,{href:"https://github.com/opencontainers/image-spec/blob/main/artifacts-guidance.md",children:"Guidance for Artifacts\nAuthors"}),"."]}),"\n",(0,a.jsx)(t.h2,{id:"architectures",children:"Architectures"}),"\n",(0,a.jsx)(t.p,{children:"Inspektor Gadget supports multi architecture artifacts. The following\narchitectures are supported:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsx)(t.li,{children:"amd64"}),"\n",(0,a.jsx)(t.li,{children:"arm64"}),"\n"]}),"\n",(0,a.jsx)(t.h2,{id:"artifacttype",children:"ArtifactType"}),"\n",(0,a.jsxs)(t.p,{children:["Media type: ",(0,a.jsx)(t.code,{children:"application/vnd.gadget.v1+binary"})]}),"\n",(0,a.jsxs)(t.p,{children:["This indicates the manifest is a Gadget. It follows the guidelines in:\n",(0,a.jsx)(t.a,{href:"https://github.com/opencontainers/image-spec/blob/main/manifest.md#guidelines-for-artifact-usage",children:"https://github.com/opencontainers/image-spec/blob/main/manifest.md#guidelines-for-artifact-usage"}),"."]}),"\n",(0,a.jsx)(t.h2,{id:"gadget-metadata",children:"Gadget metadata"}),"\n",(0,a.jsxs)(t.p,{children:["Media type: ",(0,a.jsx)(t.code,{children:"application/vnd.gadget.config.v1+yaml"})]}),"\n",(0,a.jsxs)(t.p,{children:["This contains the ",(0,a.jsx)(t.a,{href:"/docs/v0.54.1/gadget-devel/metadata",children:"gadget metadata"}),"."]}),"\n",(0,a.jsx)(t.h2,{id:"image-layers-and-media-types",children:"Image layers and media types"}),"\n",(0,a.jsx)(t.p,{children:"Each architecture can contain several layers, but each layer must have a\ndifferent media type among the following:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.code,{children:"application/vnd.gadget.ebpf.program.v1+binary"})}),"\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.code,{children:"application/vnd.gadget.wasm.program.v1+binary"})}),"\n",(0,a.jsx)(t.li,{children:(0,a.jsx)(t.code,{children:"application/vnd.gadget.btfgen.v1+binary"})}),"\n"]}),"\n",(0,a.jsx)(t.h3,{id:"the-ebpf-layer",children:"The ebpf layer"}),"\n",(0,a.jsxs)(t.p,{children:["There must be exactly one layer with the ebpf media type. It must not be empty.\nIts content must be a valid ELF file. See ",(0,a.jsx)(t.a,{href:"/docs/v0.54.1/gadget-devel/gadget-ebpf-api",children:"gadget eBPF\nAPI"}),"."]}),"\n",(0,a.jsx)(t.h3,{id:"the-wasm-layer",children:"The wasm layer"}),"\n",(0,a.jsxs)(t.p,{children:["There must be at most one layer with the wasm media type. If present, it must\nnot be empty and it must be a valid wasm file. See ",(0,a.jsx)(t.a,{href:"/docs/v0.54.1/gadget-devel/gadget-wasm-api-raw",children:"WASM\nAPI"}),"."]}),"\n",(0,a.jsx)(t.h3,{id:"the-btfgen-layer",children:"The btfgen layer"}),"\n",(0,a.jsxs)(t.p,{children:[(0,a.jsx)(t.a,{href:"https://www.inspektor-gadget.io
1/blog/2022/03/btfgen-one-step-closer-to-truly-portable-ebpf-programs/",children:"btfgen"}),"\nis used to enable running eBPF programs on kernels that don't provide BTF information. A gadget\nimage can contain at most one btfgen layer. This layer must contain the generated BTF files in a\ntarball following the same folder structure of\n",(0,a.jsx)(t.a,{href:"https://github.com/aquasecurity/btfhub-archive/",children:"btfhub-archive"}),"."]}),"\n",(0,a.jsx)(t.h2,{id:"image-annotations",children:"Image annotations"}),"\n",(0,a.jsx)(t.p,{children:"OCI images can have annotations at different levels:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsx)(t.li,{children:"index"}),"\n",(0,a.jsx)(t.li,{children:"manifest"}),"\n",(0,a.jsx)(t.li,{children:"config"}),"\n",(0,a.jsx)(t.li,{children:"layer"}),"\n"]}),"\n",(0,a.jsx)(t.p,{children:"Inspektor Gadget automatically adds the following annotations at the manifest and config levels:"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsxs)(t.li,{children:[(0,a.jsx)(t.code,{children:"org.opencontainers.image.*"}),": defined by ",(0,a.jsx)(t.a,{href:"https://github.com/opencontainers/image-spec/blob/main/annotations.md#pre-defined-annotation-keys",children:"OCI Image Format"}),"\n",(0,a.jsxs)(t.ul,{children:["\n",(0,a.jsx)(t.li,{children:"title"}),"\n",(0,a.jsx)(t.li,{children:"description"}),"\n",(0,a.jsx)(t.li,{children:"url"}),"\n",(0,a.jsx)(t.li,{children:"documentation"}),"\n",(0,a.jsx)(t.li,{children:"source"}),"\n",(0,a.jsx)(t.li,{children:"created"}),"\n"]}),"\n"]}),"\n"]})]})}function h(e={}){const{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,a.jsx)(t,{...e,children:(0,a.jsx)(l,{...e})}):l(e)}},28453:(e,t,n)=>{n.d(t,{R:()=>r,x:()=>c});var i=n(96540);const a={},s=i.createContext(a);function r(e){const t=i.useContext(s);return i.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function c(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:r(e.components),i.createElement(s.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.