Uploaded image for project: 'Openshift sandboxed containers'
  1. Openshift sandboxed containers
  2. KATA-3135

support signed container images

XMLWordPrintable

    • Product / Portfolio Work
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • OCPSTRAT-2027OpenShift Confidential Containers
    • 50% To Do, 0% In Progress, 50% Done
    • Hide
      .Downstream-only signed containers no longer require manual trustee policy

      Before this update, downstream-only signed containers required manual {trustee} policy creation, causing OSC CoCo dependency and usability issues. As a consequence, downstream-only signed containers required {trustee} policy, causing pod startup failures for users. With this release, the downstream-only signed container policy has been updated for improved usability. As a result, users no longer need to create containers policy in {trustee} for pods to start, reducing dependency and error prone scenarios.
      Show
      .Downstream-only signed containers no longer require manual trustee policy Before this update, downstream-only signed containers required manual {trustee} policy creation, causing OSC CoCo dependency and usability issues. As a consequence, downstream-only signed containers required {trustee} policy, causing pod startup failures for users. With this release, the downstream-only signed container policy has been updated for improved usability. As a result, users no longer need to create containers policy in {trustee} for pods to start, reducing dependency and error prone scenarios.
    • Bug Fix
    • Proposed
    • Yes
    • 0
    • 0

      End users of coco prefers to provide either an encrypted container image or a signed container image for their workload.
      CoCo on ARO should be able to deploy workload with encrypted or signed container images.

      This feature focuses on the signed image support.

      Part of it requires guest-side components for image validation. We also need to make sure there is no limitation from the node side when creating a container with a signed image. 

              jrope Julien ROPE
              jfreiman Jens Freimann
              Victor Voronkov
              Victor Voronkov Victor Voronkov
              John Wilkins John Wilkins
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: