1+ ` ` ` toml
12algorithm = "sha384"
23version = "0.1.0"
34
@@ -7,15 +8,63 @@ version = "0.1.0"
78[token_configs.coco_as]
89url = "https://kbs-trustee-operator-system.{{ .Values.global.hubClusterDomain }}"
910
11+
1012[token_configs.kbs]
1113url = "https://kbs-trustee-operator-system.{{ .Values.global.hubClusterDomain }}"
14+ cert = """
15+ acmmagickey_trustee_cert
16+ """
1217'''
1318
1419"cdh.toml" = '''
1520socket = 'unix:///run/confidential-containers/cdh.sock'
1621credentials = []
1722
1823[kbc]
19- name = " cc_kbc"
20- url = " https://kbs-trustee-operator-system.{{ .Values.global.hubClusterDomain }}"
24+ name = 'cc_kbc'
25+ url = '<url>:<port>'
26+ kbs_cert = """
27+ acmmagickey_trustee_cert
28+ """
29+
30+ "policy.rego" = '''
31+ package agent_policy
32+
33+ default AddARPNeighborsRequest := true
34+ default AddSwapRequest := true
35+ default CloseStdinRequest := true
36+ default CopyFileRequest := true
37+ default CreateContainerRequest := true
38+ default CreateSandboxRequest := true
39+ default DestroySandboxRequest := true
40+ default ExecProcessRequest := true
41+ default GetMetricsRequest := true
42+ default GetOOMEventRequest := true
43+ default GuestDetailsRequest := true
44+ default ListInterfacesRequest := true
45+ default ListRoutesRequest := true
46+ default MemHotplugByProbeRequest := true
47+ default OnlineCPUMemRequest := true
48+ default PauseContainerRequest := true
49+ default PullImageRequest := true
50+ default ReadStreamRequest := true
51+ default RemoveContainerRequest := true
52+ default RemoveStaleVirtiofsShareMountsRequest := true
53+ default ReseedRandomDevRequest := true
54+ default ResumeContainerRequest := true
55+ default SetGuestDateTimeRequest := true
56+ default SetPolicyRequest := true
57+ default SignalProcessRequest := true
58+ default StartContainerRequest := true
59+ default StartTracingRequest := true
60+ default StatsContainerRequest := true
61+ default StopTracingRequest := true
62+ default TtyWinResizeRequest := true
63+ default UpdateContainerRequest := true
64+ default UpdateEphemeralMountsRequest := true
65+ default UpdateInterfaceRequest := true
66+ default UpdateRoutesRequest := true
67+ default WaitProcessRequest := true
68+ default WriteStreamRequest := true
2169'''
70+ ` ` `
0 commit comments