It takes one block (stored as default) or a map of named blocks (details). package and compile are mutually exclusive, as are cmdline and cmdline_extra.
Key
Type
Description
package
string
Kernel package installed at runtime install
version
string
Kernel version constraint: 6.6.*, >= 6.6, or exact. On a block by itself, it constrains every runtime.
compile
string
sdk.compile section that builds the kernel. Requires install.
install
string
Script that copies kernel artifacts to $AVOCADO_RUNTIME_BUILD_DIR
One block (stored as default) or a map of named blocks. Runtimes can reference them by name.
Key
Type
Default
Description
packages (alias dependencies)
package map
the avocado-pkg-* meta-package
Packages. {{ avocado.kernel.version }} works in keys.
filesystem
string
rootfs erofs-lz4, initramfs cpio.zst
rootfs: erofs-lz4 or erofs-zst. initramfs: cpio, cpio.zst, cpio.lz4 or cpio.gz. Extensions without their own filesystem inherit the rootfs value.
overlay
string, or { dir, mode, preprocess ◆ }
none
Copied over the sysroot after install. It never deletes files, in either mode (details). preprocess: true or a list of globs (details).
post_install ◆
string (script path)
built-in defaults
Runs on the image’s working copy before mkfs. Replaces the built-in defaults entirely: the usrmerge symlinks, the empty /etc/machine-id, systemctl preset-all and ldconfig. If you set it, redo those yourself. It receives $ROOTFS_WORK or $INITRAMFS_WORK, plus $ROOTFS_SYSROOT, $AVOCADO_PREFIX, $AVOCADO_SDK_PREFIX, $RUNTIME_NAME, $RUNTIME_VERSION and $TARGET_ARCH, and runs under set -euo pipefail.
permissions ◆
name of a permissions entry, or inline
none
Users and groups written into this image’s /etc/passwd, /etc/shadow and /etc/group
image ◆
mapping
raw
Wrapper format, same shape as extensions.<n>.image
Extension names, or single-key maps like - name: { enabled: false }. A disabled extension ships but isn’t activated. Order is merge priority: earlier wins a file conflict.
packages (alias dependencies)
package map
Runtime packages, usually avocado-runtime: '*'
target
string
Pin the runtime to one target
targets ◆
list
Scope the runtime to several targets (for per-target opt-ins like var.encrypt)
target_board
string
Board for {{ avocado.target.board }}, only when this runtime is resolved through AVOCADO_RUNTIME, default_runtime or the single-runtime rule. -r doesn’t count (details). There’s no board: key.
version ◆
string
Runtime version label. Defaults to the first 8 characters of a random UUID, new on every build, so set it if you want stable version strings.
Fetch this extension’s definition from elsewhere. include pulls in extra sections, for example provision_profiles.*. For git, set ref to a tag or branch: any other value (a commit hash, or a mistyped tag) silently builds the default branch’s tip, and the lock doesn’t record the commit (details).
version
string, or { file, key?, format? } ◆
none, and required
Quote it ('1.10', not 1.10). The mapping form reads the version from a file in the extension’s own tree; format is toml, json or yaml.
Feed packages, and compile outputs via { compile, install }
sdk
{ packages }
none
SDK packages this extension needs at build time, for example nativesdk-uv: '*'. They’re merged into the SDK install. Accepts target- overrides.
overlay
string, or { dir, mode, preprocess ◆ }
none
Files copied into the extension. Never deletes anything (details).
enable_services
list
none
Units to enable, as *.wants/ symlinks in the confext. Removing one doesn’t remove its symlink.
modprobe
list
none
Modules loaded on every merge, after daemon-reload with the other on_merge commands. A failure only warns. Changing only this list doesn’t trigger a rebuild (details).
Runs after the extension is built, with $AVOCADO_EXT_NAME, $AVOCADO_TARGET and $AVOCADO_BUILD_EXT_SYSROOT set
package_files ◆
list
the config file, all overlay directories (including target- ones), compile and install scripts
Files included when you package the extension with avocado ext package. An explicit list replaces the defaults, except that a version: { file } provider’s file is always added. It’s also hashed for up-to-date checks when the extension compiles something.
stone_include_paths ◆
list
none
Directories handed to the flash tooling, for example a carrier-bsp/ override (details)
filesystem
string
the rootfs filesystem
erofs, erofs-lz4, erofs-zst or squashfs
image ◆
{ type: raw | kab, args?, verity? }
raw
kab wraps the image with kabtool. veritymust be a real boolean.
var_files
list of globs
none
Files that go on the var partition instead of into the image
subvolumes ◆
map
none
Var subvolumes this extension needs. The first extension listed wins a conflict.
docker_images
list of { image, tag }
none
Container images pre-loaded onto the var partition
depends_on ◆
list of name, { name, version } or { name: version }
none
Other extensions this one needs. Resolved at build time.
class ◆
application or platform
application
Drives the dependency lints. An unknown value is an error.
device_tree_overlays ◆
list of { name, src, params? }
none
Device-tree overlays to compile and install on the boot medium. name must be a safe basename.