Skip to content

Conversation

@Jakob-Naucke
Copy link
Collaborator

Read initdata from config, passed to trustee-attester.

@alicefr
Copy link
Contributor

alicefr commented Nov 7, 2025

@Jakob-Naucke we decided in the design document to alwys use json for the initidata as well. I think you need some parsing of the initdata to get the uuid correctly

@Jakob-Naucke
Copy link
Collaborator Author

ah yes, the commit was older than the settlement of the discussion on trusted-execution-clusters/operator#5 and I just pulled it off the shelf sorry 🤣 let me update.

For binaries, Cargo.lock should be checked in.

Signed-off-by: Jakob Naucke <[email protected]>
@Jakob-Naucke Jakob-Naucke requested review from alicefr and removed request for alicefr November 10, 2025 12:00
@alicefr
Copy link
Contributor

alicefr commented Nov 12, 2025

@Jakob-Naucke can you please fix the linting issue?

@Jakob-Naucke
Copy link
Collaborator Author

whoops, I should pre-commit at some point

Read initdata from config, passed to trustee-attester.

Signed-off-by: Jakob Naucke <[email protected]>
@alicefr
Copy link
Contributor

alicefr commented Nov 12, 2025

/lgtm

@alicefr alicefr merged commit 366adb0 into latchset:main Nov 12, 2025
8 checks passed
@Jakob-Naucke Jakob-Naucke deleted the initdata branch November 12, 2025 10:33
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 12, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 12, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 19, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants