Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a release 3.5.0 overview blog post #248

Merged
merged 4 commits into from
Jun 13, 2024
Merged

Add a release 3.5.0 overview blog post #248

merged 4 commits into from
Jun 13, 2024

Conversation

ildikov
Copy link
Collaborator

@ildikov ildikov commented Jun 13, 2024

This patch adds a new blog post to provide highlights of the latest, 3.5.0 release of Kata Containers.

This patch adds a new blog post to provide highlights of the latest,
3.5.0 release of Kata Containers.

Signed-off-by: Ildiko Vancsa <ildiko.vancsa@gmail.com>
Copy link

netlify bot commented Jun 13, 2024

Deploy Preview for katacontainers ready!

Name Link
🔨 Latest commit 7058d20
🔍 Latest deploy log https://app.netlify.com/sites/katacontainers/deploys/666b02c9e9cb240008b3bc67
😎 Deploy Preview https://deploy-preview-248--katacontainers.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.


2. Security Enhancements

The kata-agent now includes the latest ‘libseccomp’ v2.5.5 to improve security. Please note that this library is licensed under [GNU LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html). The version used by Kata Containers is not modified from the upstream version, and you can find the complete source code for the library attached for full compliance.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The libseccomp bump went into 3.4.0

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, good clarification. I saw the notice in the release notes and I thought that meant it was bumped in this release. I will update the blog post title to allow for more updates than just 3.5.0, and leave this here as a note.


The kata-agent now includes the latest ‘libseccomp’ v2.5.5 to improve security. Please note that this library is licensed under [GNU LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html). The version used by Kata Containers is not modified from the upstream version, and you can find the complete source code for the library attached for full compliance.

In addition, ‘rootfs’ is now built with≈ with ‘AGENT_POLICY=yes’ by default for increased security and stability.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's worth mentioning related to this that in 3.5.0 we changed the policy implementation from the golang based OPA binary to the regorus crate, which should give improved performances and a smaller rootfs and memory performance of the guest.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This might be in new features section though.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added it under the new features section.

Signed-off-by: Ildiko Vancsa <ildiko.vancsa@gmail.com>
Copy link
Collaborator Author

@ildikov ildikov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@stevenhorsman Thank you for the speedy review, I updated the article to address your comments. Please let me know if the content looks good to go.


2. Security Enhancements

The kata-agent now includes the latest ‘libseccomp’ v2.5.5 to improve security. Please note that this library is licensed under [GNU LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html). The version used by Kata Containers is not modified from the upstream version, and you can find the complete source code for the library attached for full compliance.
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, good clarification. I saw the notice in the release notes and I thought that meant it was bumped in this release. I will update the blog post title to allow for more updates than just 3.5.0, and leave this here as a note.


The kata-agent now includes the latest ‘libseccomp’ v2.5.5 to improve security. Please note that this library is licensed under [GNU LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html). The version used by Kata Containers is not modified from the upstream version, and you can find the complete source code for the library attached for full compliance.

In addition, ‘rootfs’ is now built with≈ with ‘AGENT_POLICY=yes’ by default for increased security and stability.
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added it under the new features section.

Copy link
Member

@stevenhorsman stevenhorsman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the updates

@ildikov
Copy link
Collaborator Author

ildikov commented Jun 13, 2024

Awesome, thank you for the quick review! I'll publish this since 3.6.0 is knocking on the door now. :)

@ildikov ildikov merged commit 3834d4f into main Jun 13, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants