Conversation
Removes TdxConfigSpec and related configuration for Intel TDX quote verification that required connectivity to external PCCS servers. This simplifies the operator for disconnected/air-gapped environments where PCCS access is not available. Changes: - Remove TdxConfigSpec from KbsConfig API and CRD - Delete tdx-config.json template and sample configurations - Remove TDX helper functions and controller logic - Clean up TDX-related documentation and test assertions Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
TDX disconnected environment
Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Updated the KbsConfigReconciler to use the new events API: - Updated Recorder type from record.EventRecorder to events.EventRecorder - Replaced mgr.GetEventRecorderFor() with mgr.GetEventRecorder() - Converted all Event() calls to Eventf() calls with the new signature: Eventf(regarding, related, eventtype, reason, action, note, args...) Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
This commit implements a general mechanism to automatically restart KBS workload pods when any mounted ConfigMap changes. This solves a common Kubernetes limitation: ConfigMap content updates don't automatically restart pods, so configuration changes (policies, reference values, TLS settings) wouldn't take effect without manual intervention. Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
When deploying with a custom IMG (e.g., IMG=trustee-operator:local-test), the Makefile now updates both: 1. The operator container image (existing behavior) 2. The OPERATOR_IMAGE_NAME environment variable (new fix) This ensures that the secret-converter init container uses the same image as the operator, which is critical for local development and testing. Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Added more PCR values to check At the momement we don't know how to populate the following fields in RVPS database, so commenting them out: - measurement - reported-tcb* - [platform|policy] fields - [mr_td|xfam] fields Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Fix attestation policy for Azure SNP/TDX
Bumped operator versions for Kubernetes 1.35
Auto rollout of Trustee deployment
- Add ibmSE field to TrusteeConfigSpec to enable IBM SE mode - Add pvName field to IbmSETeeConfig (accessed as spec.ibmSE.pvName) - Add RBAC for PersistentVolumeClaims and PersistentVolumes - Add IBM SE PVC creation and reconciliation in ibmse_helper.go - Skip CPU/GPU attestation policies for IBM SE deployments - Move IBM SE functions to ibmse_helper.go - Update IBM SE docs for new TrusteeConfig-based workflow - Add sample IBM SE resource policy config/templates/resource-policy-ibm.rego - Update resource_policy_helper.go to use IBM SE template when ibmSE is set - When ibmSE is removed from the trusteeconfig ,normal flow restored. - Regenerate bundle Signed-off-by: Chathurya Adapa <Adapa.Chathurya1@ibm.com> Assisted-by: IBM Bob noreply@ibm.com
…r-ibmse-upstream support IBM SE TrusteeConfig provisioning
updateKbsDeployment() unconditionally called r.Update() on every reconciliation even when the deployment spec had not changed. Since the controller watches its own Deployment (Owns), the resourceVersion bump from the no-op update re-triggers reconciliation, creating a tight infinite loop. Add a DeepEqual check on the pod template and replicas before calling Update, and only emit the "Updated Deployment" log/event when an actual change was written. Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
buildEnvVars() merges cluster proxy settings and user-specified KbsEnvVars via a map, then iterates the map to build []EnvVar. Go map iteration is non-deterministic, so with multiple env vars (e.g. proxy settings + RUST_LOG) the container env ordering can differ between reconciliations, producing a different pod template hash and triggering unnecessary rollouts. Sort the resulting slice by env var name for stable ordering. Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
Fix infinite loop reconcile
Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Now we can have multiples cert files under the HW-ID directory. The cert filename is prefixed with the tcb for allowing smooth firmware upgrades. The old filename vcek.der is still valid as backward compatiblity fallback Signed-off-by: Leonardo Milleri <lmilleri@redhat.com>
Signed-off-by: Neeraj Krishna Gopalakrishna <ngopalak@redhat.com>
Signed-off-by: Neeraj Krishna Gopalakrishna <ngopalak@redhat.com>
…e-labels add labels to secrets created by operator
…-endpoint Enable health endpoint on the kbs pods
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Repository: openshift/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: Comment |
Signed-off-by: Daniel Kreling <dkreling@redhat.com>
dbkreling
force-pushed
the
fix/CVE-2026-56852
branch
from
September 8, 2026 13:34
760b038 to
491064d
Compare
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps golang.org/x/text from v0.37.0 to v0.39.0 to resolve CVE-2026-56852.
CVE: CVE-2026-56852
Vulnerable range: < v0.39.0
Fixed in: v0.39.0
Jira ticket: KATA-5824
A
norm.Iterin golang.org/x/text can enter an infinite loop when handling input containing invalid UTF-8 bytes.This PR was created by the
kata-bug-triageskill and supervised by Daniel Kreling.