Skip to content

feat: adding airgap support - #38

Merged
butler54 merged 6 commits into
validatedpatterns:mainfrom
butler54:dev/airgap-testing
Aug 17, 2026
Merged

feat: adding airgap support#38
butler54 merged 6 commits into
validatedpatterns:mainfrom
butler54:dev/airgap-testing

Conversation

@butler54

Copy link
Copy Markdown
Collaborator

No description provided.

butler54 and others added 6 commits July 23, 2026 12:53
…(D-08, D-09, D-11, D-11b)

- Add kbsLocalCertCacheSpec to KbsConfig CR template, gated by kbs.tdx.enabled,
  mounting tdx-collateral Secret at configurable mount path
- Change collateralService default from Intel PCS HTTPS URL to file:// URL
  pointing to mounted collateral JSON for offline verification
- Add collateralMountPath and collateralFileName values for path consistency
- Create tdx-collateral-eso.yaml ExternalSecret pulling from Vault
  secret/data/hub/tdxCollateral into tdx-collateral Secret
- Add dcap_verifier section to kbs-config-map.yaml with collateral_service
  and tcb_update_type = "early" for offline verification
Add registry-ca-eso.yaml to deliver private registry CA certificates
from Vault to the imperative namespace, enabling CoCo guests to trust
private registries. Gated on kbs.registryCa.enabled (default false).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add kbs.snp.enabled toggle with per-node VCEK certificate injection
via kbsLocalCertCacheSpec. Supports airgapped environments where AMD
KDS is unreachable.

- values.yaml: new kbs.snp section (enabled, vcekSecrets list)
- snp-vcek-eso.yaml: ExternalSecret per hardware ID
- kbs.yaml: combined TDX+SNP kbsLocalCertCacheSpec
- kbs-config-map.yaml: snp_verifier with OfflineStore

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Chris Butler <chris.butler@redhat.com>
Signed-off-by: Chris Butler <chris.butler@redhat.com>
@butler54
butler54 merged commit 4ece12a into validatedpatterns:main Aug 17, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant