Conversation
|
Skipping CI for Draft Pull Request. |
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
600de20 to
74d0320
Compare
…-CVM pods Add a mutating admission webhook in the operator that automatically injects a permissive initdata annotation on peer-pod pods using non-confidential VM instance types. This allows exec and logs to work on standard (TrustedLaunch) VMs while keeping the restrictive default policy for confidential VMs (SEV-SNP). The webhook creates its own cluster-wide MutatingWebhookConfiguration at startup instead of relying on OLM's webhookdefinitions, which would scope it to the operator namespace only. The CA bundle is read from the OLM-managed cert secret. The webhook reads CLOUD_PROVIDER from peer-pods-cm to determine the cloud platform (currently Azure, extensible to AWS and others). When the pod has no machine_type annotation, it falls back to AZURE_INSTANCE_SIZE to determine confidentiality. Pods that already carry a cc_init_data annotation are left untouched. Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
|
Reminder to self: also update the kata-remote enable_annotation list in configuration.toml |
Add a mutating admission webhook in the operator that automatically injects a permissive initdata annotation on peer-pod pods using non-confidential VM instance types. This allows exec and logs to work on standard (TrustedLaunch) VMs while keeping the restrictive default policy for confidential VMs (SEV-SNP).
The webhook reads CLOUD_PROVIDER from peer-pods-cm to determine the cloud platform (currently Azure, extensible to AWS and others). When the pod has no machine_type annotation, it falls back to AZURE_INSTANCE_SIZE to determine confidentiality. Pods that already carry a cc_init_data annotation are left untouched.
This effectively replaces the feature gate in Azure.
- Description of the problem which is fixed/What is the use case
- What I did
- How to verify it
- Description for the changelog