-
Epic
-
Resolution: Unresolved
-
Medium
-
None
-
None
-
None
-
None
-
Create integrity-protected pod VM image Azure
-
5
-
False
-
None
-
False
-
Not Selected
-
To Do
-
-
-
No
-
0
-
0.000
Epic Goal
- Create integrity-protected pod VM image
Why is this important?
- For CoCo, it's important to ensure that the VM image has not been tampered with, otherwise secrets can be exfiltrated via tampered software.
Scenarios
- ...
- ...
Acceptance Criteria
(The Epic is complete when...)
- Instructions to create dm-verity protected CVM image for peer-pods via operator or standalone
- Instructions to generate measurements of the image
- Verifying the measurements via KBS
Additional context:
Upstream has a method that is described in the following blog
Vitaly has instructions on how create dm-verity protected CVM images in public cloud
- is depended on by
-
KATA-2715 Create measurements for all the components used in the CoCo stack
- In Progress