Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
fd99dc8
Remove TDX PCCS-dependent configuration
lmilleri Jun 9, 2026
a2a0435
Merge pull request #162 from lmilleri/tdx-disconnected
lmilleri Jun 10, 2026
4bc7c7a
Bumped operator versions for Kubernetes 1.35
lmilleri Jun 15, 2026
a48358c
Replace deprecated GetEventRecorderFor with GetEventRecorder
lmilleri Jun 16, 2026
6c67e88
Automatic KBS pod restart on ConfigMap changes
lmilleri Jun 17, 2026
a4978c1
Fix Makefile deploy to update OPERATOR_IMAGE_NAME env var
lmilleri Jun 17, 2026
a751f57
Fix attestation policy for Azure SNP/TDX
lmilleri Jun 18, 2026
78fecb5
Merge pull request #165 from lmilleri/fix-azure-policy
lmilleri Jun 19, 2026
75bcb9f
Merge pull request #163 from lmilleri/bump-operator-sdk
lmilleri Jun 19, 2026
7cf119c
Merge pull request #164 from lmilleri/auto-rollout
lmilleri Jun 19, 2026
87bd0dc
feat: support IBM SE TrusteeConfig provisioning
chathuryaadapa Jun 23, 2026
ac6cca2
Merge pull request #166 from chathuryaadapa/enhance-trusteecr-ibmse-u…
lmilleri Jul 1, 2026
4785fae
fix: skip deployment update when spec is unchanged
esposem Jul 16, 2026
ad72f19
fix: sort env vars to ensure deterministic deployment spec
esposem Jul 16, 2026
609ca77
Merge pull request #167 from esposem/ufix
lmilleri Jul 17, 2026
ef1ede6
Bump operator version v0.21.0
lmilleri Jul 31, 2026
2005253
Amended AMD disconnected documentation
lmilleri Jul 31, 2026
7a73e73
Merge pull request #170 from lmilleri/v0.21.0
lmilleri Aug 10, 2026
717e52c
add labels to secrets created by operator
ngopalak-redhat Aug 18, 2026
8c6cff9
Enable health endpoint on the pods
ngopalak-redhat Aug 18, 2026
1431f62
Merge pull request #171 from ngopalak-redhat/ngopalak/trustee-labels
lmilleri Aug 20, 2026
dec08ea
Merge pull request #172 from ngopalak-redhat/ngopalak/health-endpoint
lmilleri Aug 20, 2026
491064d
deps: bump golang.org/x/text to v0.39.0 for CVE-2026-56852
dbkreling Sep 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# To re-generate a bundle for another specific version without changing the standard setup, you can:
# - use the VERSION as arg of the bundle target (e.g make bundle VERSION=0.0.2)
# - use environment variables to overwrite this value (e.g export VERSION=0.0.2)
VERSION ?= 0.19.0
VERSION ?= 0.21.0

# CHANNELS define the bundle channels used in the bundle.
# Add a new line here if you would like to change its default config. (E.g CHANNELS = "candidate,fast,stable")
Expand Down Expand Up @@ -50,7 +50,7 @@ endif
IMG ?= controller:latest

# ENVTEST_K8S_VERSION refers to the version of kubebuilder assets to be downloaded by envtest binary.
ENVTEST_K8S_VERSION = 1.32.0
ENVTEST_K8S_VERSION = 1.35.0

# Get the currently used golang install path (in GOPATH/bin, unless GOBIN is set)
ifeq (,$(shell go env GOBIN))
Expand Down Expand Up @@ -161,7 +161,7 @@ uninstall: manifests kustomize ## Uninstall CRDs from the K8s cluster specified
.PHONY: deploy
deploy: manifests kustomize ## Deploy controller to the K8s cluster specified in ~/.kube/config.
cd config/manager && $(KUSTOMIZE) edit set image quay.io/confidential-containers/trustee-operator=${IMG}
$(KUSTOMIZE) build config/default | $(KUBECTL) apply -f -
$(KUSTOMIZE) build config/default | sed '/- name: OPERATOR_IMAGE_NAME/{n;s|value:.*|value: $(IMG)|;}' | $(KUBECTL) apply -f -

.PHONY: undeploy
undeploy: ## Undeploy controller from the K8s cluster specified in ~/.kube/config. Call with ignore-not-found=true to ignore resource not found errors during deletion.
Expand All @@ -176,8 +176,8 @@ build-installer: manifests generate kustomize ## Generate a consolidated YAML wi
# Run sample attestation in a kind cluster
# pre-requirements: kuttl plugin and kind are installed
# Usage: KBS_IMAGE_NAME=<trustee-image> CLIENT_IMAGE_NAME=<client-image> make test-e2e
KBS_IMAGE_NAME ?= ghcr.io/confidential-containers/staged-images/kbs:b2442c222485b6ec5d6dee09d5a30bb561ff3622
CLIENT_IMAGE_NAME ?= quay.io/confidential-containers/kbs-client:v0.19.0
KBS_IMAGE_NAME ?= ghcr.io/confidential-containers/key-broker-service:built-in-as-v0.21.0
CLIENT_IMAGE_NAME ?= quay.io/confidential-containers/kbs-client:v0.21.0
.PHONY: test-e2e
test-e2e:
./tests/scripts/kind-with-registry.sh
Expand All @@ -193,7 +193,7 @@ $(LOCALBIN):

## Tool Versions
KUSTOMIZE_VERSION ?= v5.4.3
CONTROLLER_TOOLS_VERSION ?= v0.18.0
CONTROLLER_TOOLS_VERSION ?= v0.21.0
ENVTEST_VERSION ?= release-0.22
GOLANGCI_LINT_VERSION ?= v2.1.0

Expand Down
14 changes: 0 additions & 14 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,10 +62,6 @@ type KbsConfigSpec struct {
// +optional
KbsResourcePolicyConfigMapName string `json:"kbsResourcePolicyConfigMapName,omitempty"`

// TdxConfigSpec is the struct that hosts the TDX specific configuration
// +optional
TdxConfigSpec TdxConfigSpec `json:"tdxConfigSpec,omitempty"`

// IbmSEConfigSpec is the struct that hosts the IBMSE specific configuration
// +optional
IbmSEConfigSpec IbmSEConfigSpec `json:"ibmSEConfigSpec,omitempty"`
Expand All @@ -84,13 +80,6 @@ type IbmSEConfigSpec struct {
CertStorePvc string `json:"certStorePvc,omitempty"`
}

// TdxConfigSpec defines the desired state for TDX configuration
type TdxConfigSpec struct {
// kbsTdxConfigMapName is the name of the configmap containing sgx_default_qcnl.conf file
// +optional
KbsTdxConfigMapName string `json:"kbsTdxConfigMapName,omitempty"`
}

// KbsLocalCertCacheSpec defines the configuration for mounting local certificates into trustee file system
type KbsLocalCertCacheSpec struct {
// SecretName is the name of the secret that maps to a local directory containing the certificates
Expand Down Expand Up @@ -212,9 +201,6 @@ spec:
kbsAttestationPolicyConfigMapName: attestation-policy
# Resource policy
kbsResourcePolicyConfigMapName: resource-policy
# TDX settings
tdxConfigSpec:
kbsTdxConfigMapName: tdx-config-sample
# IBMSE settings
ibmSEConfigSpec:
certStorePvc: ibmse-pvc
Expand Down
27 changes: 16 additions & 11 deletions api/v1alpha1/kbsconfig_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -36,13 +36,6 @@ const (
DeploymentTypeMicroservices DeploymentType = "MicroservicesDeployment"
)

// TdxConfigSpec defines the desired state for TDX configuration
type TdxConfigSpec struct {
// kbsTdxConfigMapName is the name of the configmap containing sgx_default_qcnl.conf file
// +optional
KbsTdxConfigMapName string `json:"kbsTdxConfigMapName,omitempty"`
}

// IbmSEConfigSpec defines the desired state for IBMSE configuration
type IbmSEConfigSpec struct {
// certStorePvc is the name of the PeristentVolumeClaim where certificates/keys are mounted
Expand Down Expand Up @@ -206,10 +199,6 @@ type KbsConfigSpec struct {
// +optional
KbsResourcePolicyConfigMapName string `json:"kbsResourcePolicyConfigMapName,omitempty"`

// TdxConfigSpec is the struct that hosts the TDX specific configuration
// +optional
TdxConfigSpec TdxConfigSpec `json:"tdxConfigSpec,omitempty"`

// IbmSEConfigSpec is the struct that hosts the IBMSE specific configuration
// +optional
IbmSEConfigSpec IbmSEConfigSpec `json:"ibmSEConfigSpec,omitempty"`
Expand Down Expand Up @@ -288,6 +277,16 @@ const (
ProfileTypeRestrictive ProfileType = "Restricted"
)

// IbmSETeeConfig holds IBM Secure Execution specific configuration.
// Its presence in the spec enables IBM SE mode.
type IbmSETeeConfig struct {
// PVName is the name of the pre-existing PersistentVolume that holds the IBM SE
// certificates and keys (mounted at /opt/confidential-containers/ibmse on worker nodes).
// The PV must be created by the cluster administrator before the TrusteeConfig is applied.
// The operator creates a PVC that binds to this PV and wires it into the KbsConfig.
PVName string `json:"pvName"`
}

// TrusteeConfigSpec defines the desired state of TrusteeConfig
type TrusteeConfigSpec struct {
// HttpsSpec is the struct that hosts the HTTPS configuration
Expand All @@ -301,6 +300,12 @@ type TrusteeConfigSpec struct {
// ProfileType determines how to configure trustee, e.g. in permissive/restricted mode etc.
Profile ProfileType `json:"profileType,omitempty"`

// IbmSE enables IBM Secure Execution mode when set.
// The operator will create a PVC bound to the named PV and wire it into the KbsConfig.
// CPU/GPU attestation policy ConfigMaps are skipped when this field is set.
// +optional
IbmSE *IbmSETeeConfig `json:"ibmSE,omitempty"`

// KbsServiceType is the type of service to create for KBS
// Default value is ClusterIP
// +optional
Expand Down
36 changes: 20 additions & 16 deletions api/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion bundle.Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ LABEL operators.operatorframework.io.bundle.manifests.v1=manifests/
LABEL operators.operatorframework.io.bundle.metadata.v1=metadata/
LABEL operators.operatorframework.io.bundle.package.v1=trustee-operator
LABEL operators.operatorframework.io.bundle.channels.v1=alpha
LABEL operators.operatorframework.io.metrics.builder=operator-sdk-v1.42.0
LABEL operators.operatorframework.io.metrics.builder=operator-sdk-v1.42.3
LABEL operators.operatorframework.io.metrics.mediatype.v1=metrics+v1
LABEL operators.operatorframework.io.metrics.project_layout=go.kubebuilder.io/v4

Expand Down
11 changes: 1 addition & 10 deletions bundle/manifests/confidentialcontainers.org_kbsconfigs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.18.0
controller-gen.kubebuilder.io/version: v0.21.0
creationTimestamp: null
name: kbsconfigs.confidentialcontainers.org
spec:
Expand Down Expand Up @@ -163,15 +163,6 @@ spec:
KbsServiceType is the type of service to create for KBS
Default value is ClusterIP
type: string
tdxConfigSpec:
description: TdxConfigSpec is the struct that hosts the TDX specific
configuration
properties:
kbsTdxConfigMapName:
description: kbsTdxConfigMapName is the name of the configmap
containing sgx_default_qcnl.conf file
type: string
type: object
type: object
status:
description: KbsConfigStatus defines the observed state of KbsConfig
Expand Down
18 changes: 17 additions & 1 deletion bundle/manifests/confidentialcontainers.org_trusteeconfigs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.18.0
controller-gen.kubebuilder.io/version: v0.21.0
creationTimestamp: null
name: trusteeconfigs.confidentialcontainers.org
spec:
Expand Down Expand Up @@ -58,6 +58,22 @@ spec:
that contains the TLS certificate and private key
type: string
type: object
ibmSE:
description: |-
IbmSE enables IBM Secure Execution mode when set.
The operator will create a PVC bound to the named PV and wire it into the KbsConfig.
CPU/GPU attestation policy ConfigMaps are skipped when this field is set.
properties:
pvName:
description: |-
PVName is the name of the pre-existing PersistentVolume that holds the IBM SE
certificates and keys (mounted at /opt/confidential-containers/ibmse on worker nodes).
The PV must be created by the cluster administrator before the TrusteeConfig is applied.
The operator creates a PVC that binds to this PV and wires it into the KbsConfig.
type: string
required:
- pvName
type: object
kbsServiceType:
description: |-
KbsServiceType is the type of service to create for KBS
Expand Down
37 changes: 28 additions & 9 deletions bundle/manifests/trustee-operator.clusterserviceversion.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ metadata:
alm-examples: '[]'
capabilities: Basic Install
categories: Security
containerImage: quay.io/confidential-containers/trustee-operator:v0.19.0
createdAt: "2026-05-21T15:49:55Z"
containerImage: quay.io/confidential-containers/trustee-operator:v0.21.0
createdAt: "2026-07-01T09:49:27Z"
features.operators.openshift.io/disconnected: "true"
features.operators.openshift.io/fips-compliant: "false"
features.operators.openshift.io/proxy-aware: "true"
Expand All @@ -15,10 +15,10 @@ metadata:
features.operators.openshift.io/token-auth-azure: "false"
features.operators.openshift.io/token-auth-gcp: "false"
operatorframework.io/suggested-namespace: trustee-operator-system
operators.operatorframework.io/builder: operator-sdk-v1.42.0
operators.operatorframework.io/builder: operator-sdk-v1.42.3
operators.operatorframework.io/project_layout: go.kubebuilder.io/v4
support: Confidential Containers Community
name: trustee-operator.v0.19.0
name: trustee-operator.v0.21.0
namespace: placeholder
spec:
apiservicedefinitions: {}
Expand Down Expand Up @@ -62,6 +62,25 @@ spec:
verbs:
- get
- update
- apiGroups:
- ""
resources:
- persistentvolumeclaims
verbs:
- create
- delete
- get
- list
- update
- watch
- apiGroups:
- ""
resources:
- persistentvolumes
verbs:
- get
- list
- watch
- apiGroups:
- apps
resources:
Expand Down Expand Up @@ -160,16 +179,16 @@ spec:
fieldRef:
fieldPath: metadata.namespace
- name: OPERATOR_IMAGE_NAME
value: quay.io/confidential-containers/trustee-operator:v0.19.0
value: quay.io/confidential-containers/trustee-operator:v0.21.0
- name: KBS_IMAGE_NAME
value: ghcr.io/confidential-containers/staged-images/kbs:b2442c222485b6ec5d6dee09d5a30bb561ff3622
- name: KBS_IMAGE_NAME_MICROSERVICES
value: ghcr.io/confidential-containers/key-broker-service:v0.19.0
value: ghcr.io/confidential-containers/key-broker-service:v0.21.0
- name: AS_IMAGE_NAME
value: ghcr.io/confidential-containers/staged-images/coco-as-grpc:latest
- name: RVPS_IMAGE_NAME
value: ghcr.io/confidential-containers/staged-images/rvps:latest
image: quay.io/confidential-containers/trustee-operator:v0.19.0
image: quay.io/confidential-containers/trustee-operator:v0.21.0
livenessProbe:
httpGet:
path: /healthz
Expand Down Expand Up @@ -262,5 +281,5 @@ spec:
provider:
name: Confidential Containers Community
url: https://github.com/confidential-containers
replaces: trustee-operator.v0.18.0
version: 0.19.0
replaces: trustee-operator.v0.19.0
version: 0.21.0
2 changes: 1 addition & 1 deletion bundle/metadata/annotations.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ annotations:
operators.operatorframework.io.bundle.metadata.v1: metadata/
operators.operatorframework.io.bundle.package.v1: trustee-operator
operators.operatorframework.io.bundle.channels.v1: alpha
operators.operatorframework.io.metrics.builder: operator-sdk-v1.42.0
operators.operatorframework.io.metrics.builder: operator-sdk-v1.42.3
operators.operatorframework.io.metrics.mediatype.v1: metrics+v1
operators.operatorframework.io.metrics.project_layout: go.kubebuilder.io/v4

Expand Down
11 changes: 1 addition & 10 deletions config/crd/bases/confidentialcontainers.org_kbsconfigs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.18.0
controller-gen.kubebuilder.io/version: v0.21.0
name: kbsconfigs.confidentialcontainers.org
spec:
group: confidentialcontainers.org
Expand Down Expand Up @@ -163,15 +163,6 @@ spec:
KbsServiceType is the type of service to create for KBS
Default value is ClusterIP
type: string
tdxConfigSpec:
description: TdxConfigSpec is the struct that hosts the TDX specific
configuration
properties:
kbsTdxConfigMapName:
description: kbsTdxConfigMapName is the name of the configmap
containing sgx_default_qcnl.conf file
type: string
type: object
type: object
status:
description: KbsConfigStatus defines the observed state of KbsConfig
Expand Down
Loading