This repository was archived by the owner on Feb 1, 2026. It is now read-only.
crd: Expose "UsingNFD" to the CcInstallConfig#243
Draft
fidencio wants to merge 1 commit intoconfidential-containers:mainfrom
Draft
crd: Expose "UsingNFD" to the CcInstallConfig#243fidencio wants to merge 1 commit intoconfidential-containers:mainfrom
fidencio wants to merge 1 commit intoconfidential-containers:mainfrom
Conversation
Let's have a explicit toggle that allows users to specify whether they're relying on NFD or not. In case they're not relying on NFD, business as usual. In case they are, then the runtime payload will be able to create a specific NodeFeatureRule, adapt the podOverhead of the runtime class, and make sure the keys book-keeping is correctly done. Right now, on the Kata Containers side of the things, only TDX is capable of doing so, but it's easy to expand in case other TEEs want to do the same. Signed-off-by: Fabiano Fidêncio <fabiano.fidencio@intel.com>
Member
Author
|
A few notes for the reviewers.
|
Member
Author
|
JFYI, this one will be material for the v0.9.0 release, not for this one. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Let's have a explicit toggle that allows users to specify whether they're relying on NFD or not.
In case they're not relying on NFD, business as usual. In case they are, then the runtime payload will be able to create a specific NodeFeatureRule, adapt the podOverhead of the runtime class, and make sure the keys book-keeping is correctly done.
Right now, on the Kata Containers side of the things, only TDX is capable of doing so, but it's easy to expand in case other TEEs want to do the same.