Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

versions: update kbs image tag #1789

Conversation

kartikjoshi21
Copy link
Contributor

Update kbs image tag to make it compatible with current guest component and caa.

Fixes: #1785

Update kbs image tag to make it compatible with current
guest component and caa.

Fixes: confidential-containers#1785
Signed-off-by: Kartik Joshi <kartikjoshi@microsoft.com>
@stevenhorsman
Copy link
Member

@kartikjoshi21 - is this required for the 0.8.1 release? or something for after that?

@mkulke
Copy link
Contributor

mkulke commented Apr 12, 2024

@kartikjoshi21 - is this required for the 0.8.1 release? or something for after that?

I wouldn't say it's required. this is part of the kbs remote-attestation tests that are still WIP

Copy link
Contributor

@mkulke mkulke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you quickly explain why exactly this hash?

@surajssd
Copy link
Member

Can you quickly explain why exactly this hash?

I think it is one of those images that gets built on each merge to main. And this is the one compatible with the current guest-components version.

@huoqifeng
Copy link
Contributor

I'm not sure whether this is right PR to discuss but we know KBS consists of the resource-service, attestation-service and the RVPS-service. Is the new tag (I guess it'll be deployed when do e2e test) includes all these services?

@kartikjoshi21
Copy link
Contributor Author

I'm not sure whether this is right PR to discuss but we know KBS consists of the resource-service, attestation-service and the RVPS-service. Is the new tag (I guess it'll be deployed when do e2e test) includes all these services?

This is trustee repository commit tag which is compatible with current guest component version. It is used to clone trustee repo to working directory of test and to fetch kbs image.

@mkulke
Copy link
Contributor

mkulke commented Apr 15, 2024

I'm not sure whether this is right PR to discuss but we know KBS consists of the resource-service, attestation-service and the RVPS-service. Is the new tag (I guess it'll be deployed when do e2e test) includes all these services?

yes it should

@kartikjoshi21 kartikjoshi21 merged commit a8c2f89 into confidential-containers:main Apr 15, 2024
18 checks passed
@kartikjoshi21 kartikjoshi21 deleted the kartikjoshi21/update-kbs-image-tag branch April 15, 2024 17:40
@stevenhorsman
Copy link
Member

This was reverted in #1800, so will need re-applying

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CAA: Add test for runtime key release in kbs
5 participants