Skip to content

docs: add bare metal reference documentation#75

Draft
butler54 wants to merge 1 commit intovalidatedpatterns:mainfrom
butler54:baremetal-docs
Draft

docs: add bare metal reference documentation#75
butler54 wants to merge 1 commit intovalidatedpatterns:mainfrom
butler54:baremetal-docs

Conversation

@butler54
Copy link
Copy Markdown
Collaborator

Summary

  • Add NFD matchAll bug report documenting the workaround for Node Feature Discovery rule behavior
  • Add PCR reference values guide for bare metal attestation with Intel TDX and AMD SEV-SNP

Test plan

  • Verify markdown renders correctly on GitHub
  • Review docs for accuracy against current bare metal setup procedures

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
butler54 added a commit to butler54/coco-pattern that referenced this pull request Apr 30, 2026
…lidatedpatterns#75 documentation

This commit addresses all review comments from bpradipt and pawelpros on
PR validatedpatterns#73, merges documentation from PR validatedpatterns#75, and updates container images.

Documentation changes:
- README: Replace "peer-pod infrastructure" wording to clarify Azure vs bare metal
- README: Update OCP version requirements from 4.17+ to 4.19.28+ (OSC 1.12 requirement)
- README: Clarify PCR collection differs for Azure (get-pcr.sh) vs bare metal (manual)
- README: Distinguish Azure (kata-remote) from bare metal (kata-cc) runtime classes
- values-secret.yaml.template: Add missing kbsPrivateKey secret
- values-secret.yaml.template: Reorganize with clear section headers and improved docs
- gen-secrets.sh: Add prominent alert when values-secret file is created
- Merge docs/nfd-matchall-bug.md from PR validatedpatterns#75 (NFD matchAll bug report)
- Merge docs/pcr-reference-values-bare-metal.md from PR validatedpatterns#75 (PCR collection guide)

Code cleanup:
- Delete obsolete qgs-config-cm.yaml (QGS args now inline)
- Delete obsolete qgs-sgx-cm.yaml (QCNL config via downwardAPI)
- Remove commented-out detect-runtime-class reference in values-baremetal.yaml

Image updates:
- intel-dpo-sgx.yaml: Update intel-sgx-plugin to sha256:4ac8769c (v0.35.0)
- pccs-deployment.yaml: Update osc-pccs to sha256:edf57087 (v1.12)
- qgs-ds.yaml: Update osc-tdx-qgs to sha256:308d66da (v1.12)

Resolves review comments from:
- bpradipt: peer-pod wording, OCP versions, PCR clarification
- pawelpros: obsolete ConfigMaps, image digests, PCR requirements

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant