Uploaded image for project: 'Openshift sandboxed containers'
  1. Openshift sandboxed containers
  2. KATA-3997

Update kata-agent policy docs for CoCo

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: High High
    • OSC 1.10.0
    • OSC 1.10.0
    • Documentation
    • None
    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • Kata Sprint #271, Kata Sprint #272
    • 0

      Minor changes are required in the initdata docs to adapt the latest code flow.
      The changes are:
      1. under about-initdata_azure-cc:
      switch " the default Kata Agent policy." with " the default permissive Kata Agent policy."
      2. under creating-initdata_azure-cc:
      in the example set the following to false:

      ReadStreamRequest := false
      ExecProcessRequest := false
      SetPolicyRequest := false

      in (5) the above specified kata-agent policy is the base policy recommended for confidential containers (this is even more than recommended, we encourage users to use at least this policy )

              rhn-support-jowilkin John Wilkins
              ssheribe@redhat.com Snir sheriber
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: