Uploaded image for project: 'Openshift sandboxed containers'
  1. Openshift sandboxed containers
  2. KATA-4218

[doc] Enhance support for signed container images

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: High High
    • OSC 1.11
    • None
    • Documentation
    • None
    • Product / Portfolio Work
    • 5
    • False
    • Hide

      None

      Show
      None
    • False
    • Blanc #4, Blanc #6
    • 0

      On OSC 1.8.0 it was delivered a downstream-only implementation of signed containers because the feature wasn't fully done upstream and it was important for our relation with Microsoft to deliver it. While the feature works, it brought usability issues. For instance, user is mandatory to create the containers policy in KBS otherwise any pod will break to start. This made the OSC CoCo heavily dependent on KBS and prone to errors.

      Probably, we would need o update the following sections in Trustee docs:

      Additional resources:

      POC: wmoschet eesposit@redhat.com 

      MR: https://gitlab.cee.redhat.com/telco-team-documentation/sandboxed-containers-documentation/-/merge_requests/666 (as a part of MR for https://issues.redhat.com/browse/KATA-4327 Trustee v1.0.0 changes, Trustee part)

              gnecasov@redhat.com Gabriela Necasova
              gnecasov@redhat.com Gabriela Necasova
              Avital Pinnick
              Wainer Moschetta Wainer Moschetta
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: