Skip to content

Commit f52ae44

Browse files
authored
Add paths to allowlist for Trusted workload in values.yaml (#14)
1 parent bdf12d4 commit f52ae44

1 file changed

Lines changed: 12 additions & 14 deletions

File tree

helm/trustagent/values.yaml

Lines changed: 12 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,17 @@ config:
5353
/opt/verifier/hvs/0.1.1-dev/config/trusted-keys/privacy-ca.key
5454
/opt/verifier/hvs/0.1.1-dev/config/trusted-keys/tag-ca.key
5555
/opt/verifier/hvs/0.1.1-dev/config/tls.key
56+
/opt/kata/bin/containerd-shim-kata-v2
57+
/opt/kata/bin/qemu-system-x86_64
58+
/opt/kata/libexec/virtiofsd
59+
/opt/kata/share/defaults/kata-containers/configuration-qemu.toml
60+
/opt/kata/share/kata-containers/vmlinuz-6.12.20-1.emt3
61+
/opt/kata/share/kata-containers/trusted-vm.img
62+
/opt/kata/share/kata-qemu/qemu/bios-256k.bin
63+
/opt/kata/share/kata-qemu/qemu/efi-virtio.rom
64+
/opt/kata/share/kata-qemu/qemu/linuxboot_dma.bin
65+
/opt/kata/share/kata-qemu/qemu/pvh.bin
66+
/opt/kata/share/kata-qemu/qemu/kvmvapic.bin
5667
5768
# TODO: use {VERSION} for the versions in verifier paths
5869
# Disabled due to issues in github actions
@@ -69,24 +80,11 @@ config:
6980
# /opt/verifier/hvs/{VERSION}/config/trusted-keys/tag-ca.key
7081
# /opt/verifier/hvs/{VERSION}/config/tls.key
7182

72-
# TODO: Enable Trusted workload in allowlist
73-
# Add the following paths to the allowlist for Trusted workload
74-
# /opt/kata/bin/containerd-shim-kata-v2
75-
# /opt/kata/bin/qemu-system-x86_64
76-
# /opt/kata/libexec/virtiofsd
77-
# /opt/kata/share/defaults/kata-containers/configuration-qemu.toml
78-
# /opt/kata/share/kata-containers/vmlinuz-6.12.20-1.emt3
79-
# /opt/kata/share/kata-containers/trusted-vm.img
80-
# /opt/kata/share/kata-qemu/qemu/bios-256k.bin
81-
# /opt/kata/share/kata-qemu/qemu/efi-virtio.rom
82-
# /opt/kata/share/kata-qemu/qemu/linuxboot_dma.bin
83-
# /opt/kata/share/kata-qemu/qemu/pvh.bin
84-
# /opt/kata/share/kata-qemu/qemu/kvmvapic.bin
85-
8683
imaAllowlistFolders:
8784
- /opt/verifier/cms
8885
- /opt/verifier/authservice
8986
- /opt/verifier/hvs
87+
- /opt/kata
9088

9189
aas:
9290
# Please update the url section if aas is exposed via ingress

0 commit comments

Comments
 (0)