Skip to content

docs: DPU CA configuration options#3685

Open
chet wants to merge 1 commit into
NVIDIA:mainfrom
chet:gh-issue-3571-docs
Open

docs: DPU CA configuration options#3685
chet wants to merge 1 commit into
NVIDIA:mainfrom
chet:gh-issue-3571-docs

Conversation

@chet

@chet chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Operators need one end-to-end reference for choosing how DPUs receive the CA
bundle used to authenticate NICo. This moves the operator guidance out of #3588
so the code can merge independently while technical writer review continues.

This documents the backward-compatible legacy path, non-DPF embedded and
mounted modes, DPF legacy and mounted modes, deployment examples, staged
rollout, root rotation, certificate-chain verification, and the remaining boot
chain trust boundary.

Merge order: #3588 first, this documentation PR second. The pages describe the
product surface introduced by #3588.

Related issues

Type of Change

  • Add - New feature or capability
  • Change - Changes in existing functionality
  • Fix - Bug fixes
  • Remove - Removed features or deprecated functionality
  • Internal - Internal changes (refactoring, tests, docs, etc.)

Breaking Changes

  • This PR contains breaking changes

Documentation only. It does not change configuration defaults or runtime
behavior.

Testing

  • Unit tests added/updated

  • Integration tests added/updated

  • Manual testing performed

  • No testing required (docs, internal refactor, etc.)

  • git diff --check

  • Relative link targets and generated heading anchors verified

  • Every documented key, enum value, path, Helm value, and default cross-checked
    against feat: make DPU bootstrap CA configurable #3588

  • Changed lines reviewed against the NVIDIA documentation style guide

Additional Notes

The split includes the five operator-facing Markdown files from #3588.
Embedded comments, CLI help, Helm values comments, validation messages, and the
CI-enforced configuration reference remain with the code because they are
implementation contracts.

docs/observability/core_metrics.md is intentionally untouched.

@chet
chet requested review from a team and polarweasel as code owners July 17, 2026 19:15
@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 7933fc8a-880d-42e9-8d9c-aac4ed174af6

📥 Commits

Reviewing files that changed from the base of the PR and between 0dae3ca and 08e2863.

📒 Files selected for processing (5)
  • book/src/configuration/configurability.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md

Summary by CodeRabbit

  • Documentation
    • Added guidance for selecting bootstrap CA sources: legacy download, embedded bundle, or mounted bundle.
    • Documented fail-closed behavior when embedded or mounted CA bundles are missing or invalid.
    • Added configuration examples for non-DPF and DPF provisioning workflows.
    • Added instructions for CA rotation, certificate pinning, TLS chain validation, and secure artifact boot requirements.
    • Expanded bootable artifact, networking, and Day 0 verification guidance.

Walkthrough

The documentation adds non-DPF and DPF bootstrap CA source configuration, embedded and mounted artifact behavior, certificate-chain requirements, rotation guidance, and Day 0 verification steps.

Changes

Bootstrap CA trust

Layer / File(s) Summary
Non-DPF bootstrap CA configuration
book/src/configuration/configurability.md, docs/bootable_artifacts.md, docs/dpu-management/dpu_configuration.md
Documents legacy_download, embedded, and mounted sources, bundle paths, fail-closed behavior, operator examples, artifact handling, and configuration scope.
DPF bootstrap CA policy
docs/manuals/dpf.md
Documents [dpf].dpu_agent_bootstrap_ca, legacy URL overrides, mounted Secret/ConfigMap sources, startup behavior, rollout checks, and rotation guidance.
Operator trust and verification guidance
docs/provisioning/ip-and-network-configuration.md, book/src/configuration/configurability.md, docs/bootable_artifacts.md, docs/dpu-management/dpu_configuration.md
Adds DNS, TLS-chain, pinning, artifact-integrity, rotation, and Day 0 verification guidance.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the documentation change around DPU CA configuration options.
Description check ✅ Passed The description accurately describes the documented CA bundle selection, rollout, and trust-boundary updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@chet chet mentioned this pull request Jul 17, 2026
10 tasks
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a full review of #3685, with particular attention to documentation accuracy, internal consistency, configuration defaults, rollout guidance, and link/anchor integrity.

🐇

✅ Action performed

Full review finished.

@github-actions

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/provisioning/ip-and-network-configuration.md`:
- Line 294: Update the nico-pxe.nico row to distinguish fixed DNS
hostname/record behavior from bootstrap-CA configuration. State that the
hostname remains fixed for consumers, while DPF URL overrides and mounted Secret
or ConfigMap options configure only the bootstrap-CA source or endpoint.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: d62cf9d9-d748-4930-8304-8a88eab35bfb

📥 Commits

Reviewing files that changed from the base of the PR and between 0dae3ca and 6fc47a2.

📒 Files selected for processing (6)
  • book/src/configuration/configurability.md
  • crates/api-core/src/cfg/README.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md

Comment thread docs/provisioning/ip-and-network-configuration.md Outdated
@chet
chet force-pushed the gh-issue-3571-docs branch from 6fc47a2 to 30d4b52 Compare July 17, 2026 19:23
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a fresh full review of #3685, with attention to documentation correctness, cross-document consistency, configuration semantics, rollout safety, and link/anchor integrity.

🐇

✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Caution

Failed to replace (edit) comment. This is likely due to insufficient permissions or the comment being deleted.

Error details
putComment timed out

@chet
chet force-pushed the gh-issue-3571-docs branch from 30d4b52 to 415bc08 Compare July 17, 2026 19:55
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a fresh full review of #3685, focusing on documentation correctness, cross-document consistency, configuration semantics, rollout safety, and link/anchor integrity.

🐇

✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/provisioning/ip-and-network-configuration.md`:
- Around line 338-344: Update the DPF provisioning paragraph near the references
to dpf.dpu_agent_bootstrap_ca to include the supported complete URL-override
mode, consistent with the table. Alternatively, link directly to the
authoritative DPF configuration section documenting that mode, while preserving
the existing legacy download and mounted Secret/ConfigMap guidance.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 80eb61f5-0f12-4454-8ebb-09d95ba0cb5b

📥 Commits

Reviewing files that changed from the base of the PR and between 0dae3ca and 415bc08.

📒 Files selected for processing (5)
  • book/src/configuration/configurability.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md

Comment thread docs/provisioning/ip-and-network-configuration.md Outdated
@chet
chet force-pushed the gh-issue-3571-docs branch from 415bc08 to dafa2dd Compare July 17, 2026 20:06
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a fresh full review of #3685, focusing on documentation correctness, cross-document consistency, configuration semantics and defaults, rollout safety, and link/anchor integrity.

🐇

✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@book/src/configuration/configurability.md`:
- Around line 575-580: Standardize the operator-facing restart target name from
“nico-api” to “carbide-api” in the bootstrap CA notes at
book/src/configuration/configurability.md lines 575-580 and docs/manuals/dpf.md
lines 723-725, preserving the surrounding deployment and rotation guidance.

In `@docs/manuals/dpf.md`:
- Around line 723-729: Update the mounted-CA rotation procedure in the DPF
documentation to require creating a new versioned CA object, changing
[dpf.dpu_agent_bootstrap_ca].name, and restarting nico-api. Instruct operators
to wait for DPF reconciliation and init-container re-execution, verify the new
bundle is installed, then remove the old root and object only after successful
validation.

In `@docs/provisioning/ip-and-network-configuration.md`:
- Around line 422-423: Update the embedded trust-boundary checklist near “For
non-DPF embedded” to explicitly require Secure Boot or an equivalent trusted,
integrity-verified boot chain before enabling embedded CA trust, while
preserving the existing requirement for site-specific artifacts built with
BOOTSTRAP_CA_PATH.
- Around line 360-364: Update the intermediate-rotation guidance in the TLS
server authentication section to qualify that clients avoid bundle replacement
only when every replacement intermediate chains to the pinned root; state that
operators must update the pinned bundle when that condition is not met.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 02e1af8e-9d88-4c47-9cde-058577897f4d

📥 Commits

Reviewing files that changed from the base of the PR and between 0dae3ca and dafa2dd.

📒 Files selected for processing (5)
  • book/src/configuration/configurability.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md

Comment thread book/src/configuration/configurability.md
Comment thread docs/manuals/dpf.md Outdated
Comment thread docs/provisioning/ip-and-network-configuration.md Outdated
Comment thread docs/provisioning/ip-and-network-configuration.md Outdated
@chet
chet force-pushed the gh-issue-3571-docs branch from dafa2dd to 65e8ff1 Compare July 17, 2026 20:18
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a fresh full review of #3685, focusing on documentation correctness, cross-document consistency, configuration semantics and defaults, rollout safety, and link/anchor integrity.

🐇

✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/provisioning/ip-and-network-configuration.md`:
- Around line 427-428: Expand the DPF mounted verification checklist to inspect
every DPU agent pod, confirming the projected bundle exists at
/opt/forge/forge_root.pem and that the pod successfully completes the NICo API
TLS handshake. Retain the existing Secret/ConfigMap and key checks, and state
the verification must cover every target DPU cluster.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 3216a926-1d95-4ad8-ba5d-9475af1b1782

📥 Commits

Reviewing files that changed from the base of the PR and between dafa2dd and 65e8ff1.

📒 Files selected for processing (5)
  • book/src/configuration/configurability.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md
🚧 Files skipped from review as they are similar to previous changes (3)
  • book/src/configuration/configurability.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md

Comment thread docs/provisioning/ip-and-network-configuration.md Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/bootable_artifacts.md`:
- Around line 45-47: Require verification that every DPU installed the overlap
bundle and successfully authenticated to NICo before retiring the old root.
Apply this gate in docs/bootable_artifacts.md lines 45-47 and
book/src/configuration/configurability.md lines 571-573 after reprovisioning and
before building the bundle without the old root; in
docs/dpu-management/dpu_configuration.md lines 76-81, define “migrate the fleet”
as verified bundle installation and successful API authentication across all
DPUs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: d0b4dd05-1bc9-4e57-9be4-e6aa7de0eb89

📥 Commits

Reviewing files that changed from the base of the PR and between 0dae3ca and 65e8ff1.

📒 Files selected for processing (5)
  • book/src/configuration/configurability.md
  • docs/bootable_artifacts.md
  • docs/dpu-management/dpu_configuration.md
  • docs/manuals/dpf.md
  • docs/provisioning/ip-and-network-configuration.md

Comment thread docs/bootable_artifacts.md Outdated
Operators can choose how DPUs receive the CA bundle used to authenticate NICo. This collects every supported deployment path and the safe migration steps in one place.

Primary callouts are:

- Documents the backward-compatible legacy download, site-specific embedded BFB, and operator-mounted bundle modes.
- Shows Helm, environment-variable, site configuration, and DPF examples.
- Explains staged rollout, root rotation, certificate-chain verification, and the remaining boot-chain trust boundary.

This supports NVIDIA#3571

Signed-off-by: Chet Nichols III <chetn@nvidia.com>
@chet
chet force-pushed the gh-issue-3571-docs branch from 65e8ff1 to 08e2863 Compare July 17, 2026 20:28
@chet

chet commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai full_review, thanks!

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

@chet: Starting a fresh full review of #3685, focusing on documentation accuracy, cross-document consistency, configuration semantics, operational safety, and link/anchor integrity.

🐇 ✅

✅ Action performed

Full review finished.

chet added a commit that referenced this pull request Jul 20, 2026
DPUs currently download and install the CA served by `nico-pxe` over
unauthenticated bootstrap networking. The served bundle is also tied to
the PXE workload's outbound API trust, leaving operators without a
supported site-managed trust source and making intermediate rotation
fragile.

This PR makes bootstrap CA selection an explicit, backward-compatible
product surface across non-DPF and DPF provisioning. It preserves the
historical download when no new configuration is supplied, while
allowing operators to migrate site by site to an explicit BFB-embedded
bundle or an operator-mounted bundle.

This also separates the CA served by `/api/v0/tls/root_ca` from
`nico-pxe`'s outbound API trust and validates CA material before
installation. It does not treat a CA downloaded over the same
unauthenticated path as self-authenticating. Operator documentation and
rollout guidance are split into #3685 so this code can merge
independently.

## Related issues

- Supports #3571
- Operator documentation: #3685

## Type of Change

- [x] **Add** - New feature or capability
- [ ] **Change** - Changes in existing functionality
- [ ] **Fix** - Bug fixes
- [ ] **Remove** - Removed features or deprecated functionality
- [ ] **Internal** - Internal changes (refactoring, tests, docs, etc.)

## Breaking Changes

- [ ] **This PR contains breaking changes**

No configuration means the old behavior. The default `nico-pxe` and
`nico-dpu-agent` Helm manifests were compared with `main` and remain
byte-for-byte identical. Sites can deploy the new build first and opt
into a new trust source later without a coordinated `forged` change.

## Testing

- [x] Unit tests added/updated
- [x] Integration tests added/updated
- [x] Manual testing performed
- [ ] No testing required (docs, internal refactor, etc.)

- Focused host-support, PXE, dpu-agent, API, and DB-backed cloud-init
tests
- CA staging tests for single/multi-certificate bundles, CRLF input,
malformed PEM, private keys, atomic replacement, permissions, and
stale-file removal
- Download tests for HTTP status, size, timeout, and URL-scheme handling
- Helm lint and default/configured/invalid renders for both charts and
the umbrella chart
- `cargo make clippy`
- `cargo make carbide-lints`
- `cargo make check-workspace-deps`
- `cargo make check-format-nightly`
- `git diff --check`

## Additional Notes

### Operator configuration examples

These are independent recipes; they are not meant to be combined.

Keep the historical non-DPF download explicitly (omitting the field is
equivalent):

```toml
[dpu_config]
bootstrap_ca_source = "legacy_download"
```

Keep legacy download but serve a stable operator-owned ConfigMap bundle
from the NICo umbrella chart:

```yaml
nico-pxe:
  bootstrapRootCa:
    configMapName: forge-root-ca
    key: ca.crt
```

Use an existing Secret instead when that matches the site's
bundle-distribution workflow:

```yaml
nico-pxe:
  bootstrapRootCa:
    secretName: forge-root-ca
    key: ca.crt
```

When deploying the `nico-pxe` subchart directly, omit the umbrella key:

```yaml
bootstrapRootCa:
  configMapName: forge-root-ca
  key: ca.crt
```

For a non-Helm deployment, mount the bundle into the `nico-pxe`
container and point the process at it:

```bash
export FORGE_BOOTSTRAP_ROOT_CAFILE_PATH=/etc/nico/bootstrap/roots.pem
```

Build a site-specific non-DPF BFB and select its embedded bundle:

```bash
BOOTSTRAP_CA_PATH=/secure/site/forge-roots.pem \
  cargo make --cwd pxe build-boot-artifacts-bfb
```

```toml
[dpu_config]
bootstrap_ca_source = "embedded"
```

Use a bundle installed by the non-DPF provisioning environment at
`/opt/forge/forge_root.pem`:

```toml
[dpu_config]
bootstrap_ca_source = "mounted"
```

Retain DPF download with a complete HTTP(S) endpoint override:

```toml
[dpf.dpu_agent_bootstrap_ca]
source = "legacy_download"
url = "http://site-pxe.example.com/api/v0/tls/root_ca"
```

Mount a DPF Secret:

```toml
[dpf.dpu_agent_bootstrap_ca]
source = "mounted"
object_kind = "secret"
name = "nico-bootstrap-ca-v1"
key = "ca.crt"
```

Or use a ConfigMap already created in each target DPU cluster:

```toml
[dpf.dpu_agent_bootstrap_ca]
source = "mounted"
object_kind = "config_map"
name = "nico-bootstrap-ca-v1"
key = "ca.crt"
```

The shared DPF image intentionally does not embed a site CA. Non-DPF
embedding requires the explicit build input above and an
integrity-protected artifact/boot chain. Mounted modes fail closed
rather than silently returning to the network download.

Signed-off-by: Chet Nichols III <chetn@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant