Skip to content

coco docs: clarify platforms page and agent policy - #479

Open
mikemckiernan wants to merge 1 commit into
NVIDIA:mainfrom
manuelh-dev:mahuber/coco-agent-policy-and-platforms
Open

coco docs: clarify platforms page and agent policy#479
mikemckiernan wants to merge 1 commit into
NVIDIA:mainfrom
manuelh-dev:mahuber/coco-agent-policy-and-platforms

Conversation

@mikemckiernan

Copy link
Copy Markdown
Member

Rename the supported platforms page to include software components, and document attaching a Kata agent security policy for attested production workloads.

@github-actions

Copy link
Copy Markdown

Documentation preview

https://nvidia.github.io/cloud-native-docs/review/pr-479

@mikemckiernan mikemckiernan left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few nits, PLMK if I'm within horseshoe and hand-grenade distance.

Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/attestation.rst Outdated
Comment thread confidential-containers/configure-workloads.rst Outdated
Comment thread confidential-containers/run-sample-workload.rst
@mikemckiernan mikemckiernan self-assigned this Aug 25, 2026
@manuelh-dev
manuelh-dev force-pushed the mahuber/coco-agent-policy-and-platforms branch from 4906897 to 2e9ee25 Compare August 25, 2026 22:16
@manuelh-dev

Copy link
Copy Markdown
Contributor

@manuelh-dev
manuelh-dev force-pushed the mahuber/coco-agent-policy-and-platforms branch from 2e9ee25 to 34eea2d Compare August 25, 2026 22:49
@manuelh-dev

Copy link
Copy Markdown
Contributor

@fitzthum - one more change intended to streamline agent policy + attestation in a better way: https://github.com/NVIDIA/cloud-native-docs/compare/2e9ee2527e2445e280d6cf5a3907d90072368dc6..34eea2df421ecca92ab169c4ed9e940e99429ce1 - maybe better to read the PR again instead though.

@mikemckiernan mikemckiernan left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

I opened this PR, so GH won't allow me to approve, but I'd approve. lmk if there's anything else you need from me.

Comment thread confidential-containers/attestation.rst
Comment thread confidential-containers/configure-workloads.rst
Rename the supported platforms page to include software components,
and document attaching a Kata agent security policy for attested
production workloads.

Signed-off-by: Manuel Huber <manuelh@nvidia.com>
@manuelh-dev
manuelh-dev force-pushed the mahuber/coco-agent-policy-and-platforms branch from 34eea2d to 34e229e Compare August 27, 2026 22:57

@manuelh-dev manuelh-dev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dcmiddle dcmiddle left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good updates. A couple nits and an upstream link suggestion.

**********

* Refer to :doc:`Attestation <attestation>` for Trustee concepts and a local connectivity test.
A complete attestation process should cover the Kata Agent API surface as well as the TEE.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
A complete attestation process should cover the Kata Agent API surface as well as the TEE.
A complete attestation policy should cover the Kata Agent API surface as well as the TEE.

Comment on lines +375 to +376
The agent security policy is distinct from the Trustee attestation policy that decides whether
to release secrets.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know an easier way to phrase this but there are 3 policies. Their interrelation is captured upstream here:
https://confidentialcontainers.org/docs/getting-started/securing-workloads/#understanding-coco-policies


$ kubectl delete -f multi-gpu-kata.yaml

.. _coco-agent-security-policy:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: any reason this tag is coco-agent instead of kata-agent?
not a big deal since this string doesn't appear to the user, but it could confound refactoring in the future

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants