-
Notifications
You must be signed in to change notification settings - Fork 996
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
genpolicy: support raw block devices #9651
Labels
Projects
Comments
burgerdev
added
enhancement
Improvement to an existing feature
needs-review
Needs to be assessed by the team.
labels
May 16, 2024
burgerdev
added a commit
to burgerdev/kata-containers
that referenced
this issue
May 24, 2024
CreateContainerRequest objects can specify devices to be created inside the guest VM. This change ensures that requested devices have a corresponding entry in the PodSpec. Fixes: kata-containers#9651 Signed-off-by: Markus Rudy <mr@edgeless.systems>
burgerdev
added a commit
to burgerdev/kata-containers
that referenced
this issue
May 24, 2024
CreateContainerRequest objects can specify devices to be created inside the guest VM. This change ensures that requested devices have a corresponding entry in the PodSpec. Devices that are added to the pod dynamically, for example via the Device Plugin architecture, can be allowlisted globally by adding their definition to the settings file. Fixes: kata-containers#9651 Signed-off-by: Markus Rudy <mr@edgeless.systems>
burgerdev
added a commit
to burgerdev/kata-containers
that referenced
this issue
May 31, 2024
CreateContainerRequest objects can specify devices to be created inside the guest VM. This change ensures that requested devices have a corresponding entry in the PodSpec. Devices that are added to the pod dynamically, for example via the Device Plugin architecture, can be allowlisted globally by adding their definition to the settings file. Fixes: kata-containers#9651 Signed-off-by: Markus Rudy <mr@edgeless.systems>
burgerdev
added a commit
to burgerdev/kata-containers
that referenced
this issue
May 31, 2024
CreateContainerRequest objects can specify devices to be created inside the guest VM. This change ensures that requested devices have a corresponding entry in the PodSpec. Devices that are added to the pod dynamically, for example via the Device Plugin architecture, can be allowlisted globally by adding their definition to the settings file. Fixes: kata-containers#9651 Signed-off-by: Markus Rudy <mr@edgeless.systems>
burgerdev
added a commit
to burgerdev/kata-containers
that referenced
this issue
May 31, 2024
CreateContainerRequest objects can specify devices to be created inside the guest VM. This change ensures that requested devices have a corresponding entry in the PodSpec. Devices that are added to the pod dynamically, for example via the Device Plugin architecture, can be allowlisted globally by adding their definition to the settings file. Fixes: kata-containers#9651 Signed-off-by: Markus Rudy <mr@edgeless.systems>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Which feature do you think can be improved?
The
genpolicy
tool.How can it be improved?
genpolicy
should accept Kubernetes resources that usevolumeDevice
and create an appropriate policy for these devices.Additional Information
This should work:
Right now, it produces an error because some of the fields are not defined:
The structs need to be modified to understand volumeDevices and the policy needs to be adjusted to allow the defined devices.
cc @danmihai1
The text was updated successfully, but these errors were encountered: