-
Epic
-
Resolution: Unresolved
-
Medium
-
None
-
None
-
None
-
None
Epic Goal
- Agent policy performs additional validation for each ttRPC API requests in the Guest VM, this epic goal is to allow to configure it.
Why is this important?
- Users of peer-pods/CoCo may wan't to be able to block certain calls, due to suspecting that some components were compromised or simply to change the defaults (CoCo)
Scenarios
- Setting custom policy at podvm image creation time
- Setting custom policy at pod runtime
Acceptance Criteria
- User is able to set custom policy at podvm image creation time
- User is able to set custom policy at pod runtime
- Instructions to the customization is provided
- Tests to verify customization is applied
Additional context:
- https://issues.redhat.com/browse/KATA-3073 (development has been completed as part of this phase)