Skip to content

peer-pods: add operator webhook to inject permissive initdata for non-CVM pods - #2630

Draft
esposem wants to merge 1 commit into
openshift:develfrom
esposem:webhook
Draft

esposem wants to merge 1 commit into
openshift:develfrom
esposem:webhook

Conversation

@esposem

@esposem esposem commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Add a mutating admission webhook in the operator that automatically injects a permissive initdata annotation on peer-pod pods using non-confidential VM instance types. This allows exec and logs to work on standard (TrustedLaunch) VMs while keeping the restrictive default policy for confidential VMs (SEV-SNP).

The webhook reads CLOUD_PROVIDER from peer-pods-cm to determine the cloud platform (currently Azure, extensible to AWS and others). When the pod has no machine_type annotation, it falls back to AZURE_INSTANCE_SIZE to determine confidentiality. Pods that already carry a cc_init_data annotation are left untouched.

This effectively replaces the feature gate in Azure.

- Description of the problem which is fixed/What is the use case

- What I did

- How to verify it

- Description for the changelog

@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Aug 13, 2026
@openshift-ci

openshift-ci Bot commented Aug 13, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Aug 13, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ce503ad-9d3b-4db0-a38e-23970e01cbe1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@esposem
esposem force-pushed the webhook branch 2 times, most recently from 600de20 to 74d0320 Compare August 14, 2026 09:26
…-CVM pods

Add a mutating admission webhook in the operator that automatically
injects a permissive initdata annotation on peer-pod pods using
non-confidential VM instance types. This allows exec and logs to work
on standard (TrustedLaunch) VMs while keeping the restrictive default
policy for confidential VMs (SEV-SNP).

The webhook creates its own cluster-wide MutatingWebhookConfiguration
at startup instead of relying on OLM's webhookdefinitions, which would
scope it to the operator namespace only. The CA bundle is read from the
OLM-managed cert secret.

The webhook reads CLOUD_PROVIDER from peer-pods-cm to determine the
cloud platform (currently Azure, extensible to AWS and others). When
the pod has no machine_type annotation, it falls back to
AZURE_INSTANCE_SIZE to determine confidentiality. Pods that already
carry a cc_init_data annotation are left untouched.

Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
@esposem

esposem commented Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

Reminder to self: also update the kata-remote enable_annotation list in configuration.toml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant