Skip to content

Conversation

@mkulke
Copy link
Collaborator

@mkulke mkulke commented Sep 24, 2025

This is in preperation of a verification of reference values that we can populate with signed measurements in OCI.

The kbs config is altered to support the LocalJSON ref store and we attach a reference-values.json file to the kustomize patch so the file is mounted into the kbs pod.

By default, there is a dummy reference-values.json. This can be overridden in a TEE's e2e test if we have reference values available. Trustee should then automatically verify the values in a test that uses remote attestation and consider this in the claim.

Here would be an azure e2e-test run that is setting reference values from OCI.

@mkulke mkulke force-pushed the mkulke/assert-ref-values-in-az-kbs-test branch 2 times, most recently from b736c59 to dd3191a Compare September 24, 2025 13:27
@mkulke mkulke force-pushed the mkulke/assert-ref-values-in-az-kbs-test branch 2 times, most recently from c48defe to 2a2d9df Compare September 25, 2025 07:50
@mkulke mkulke marked this pull request as ready for review September 25, 2025 07:50
@mkulke mkulke requested a review from a team as a code owner September 25, 2025 07:50
This is in preperation of a verification of reference values that we can
populate with signed measurements in OCI.

The kbs config is altered to support the LocalJSON ref store and we
attach a reference-values.json file to the kustomize patch so the file
is mounted into the kbs pod.

drive-by-fix: https cert/key have been moved to a common folder

Signed-off-by: Magnus Kulke <[email protected]>
We retrieve the podvm measurements from the earlier podvm build step
after verifying the provenance and convert it to a reference-values.json
file that will be used when KBS is deployed in the e2e test.

Signed-off-by: Magnus Kulke <[email protected]>
@mkulke mkulke force-pushed the mkulke/assert-ref-values-in-az-kbs-test branch from 2a2d9df to cfd6ded Compare December 11, 2025 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test_e2e_libvirt Run Libvirt e2e tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants