mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-07-15 16:13:20 +00:00
doc: update Intel SGX use cases document
Installation section is not longer needed because of the latest
default kata kernel supports Intel SGX.
Include QEMU to the list of supported hypervisors.
fixes #3911
Signed-off-by: Julio Montes <julio.montes@intel.com>
(cherry picked from commit 24b29310b2
)
This commit is contained in:
parent
1da88dca4b
commit
5589b246d7
@ -21,20 +21,7 @@ CONFIG_X86_SGX_KVM=y
|
|||||||
* [Intel SGX Kubernetes device plugin](https://github.com/intel/intel-device-plugins-for-kubernetes/tree/main/cmd/sgx_plugin#deploying-with-pre-built-images)
|
* [Intel SGX Kubernetes device plugin](https://github.com/intel/intel-device-plugins-for-kubernetes/tree/main/cmd/sgx_plugin#deploying-with-pre-built-images)
|
||||||
|
|
||||||
> Note: Kata Containers supports creating VM sandboxes with Intel® SGX enabled
|
> Note: Kata Containers supports creating VM sandboxes with Intel® SGX enabled
|
||||||
> using [cloud-hypervisor](https://github.com/cloud-hypervisor/cloud-hypervisor/) VMM only. QEMU support is waiting to get the
|
> using [cloud-hypervisor](https://github.com/cloud-hypervisor/cloud-hypervisor/) and [QEMU](https://www.qemu.org/) VMMs only.
|
||||||
> Intel SGX enabled QEMU upstream release.
|
|
||||||
|
|
||||||
## Installation
|
|
||||||
|
|
||||||
### Kata Containers Guest Kernel
|
|
||||||
|
|
||||||
Follow the instructions to [setup](../../tools/packaging/kernel/README.md#setup-kernel-source-code) and [build](../../tools/packaging/kernel/README.md#build-the-kernel) the experimental guest kernel. Then, install as:
|
|
||||||
|
|
||||||
```sh
|
|
||||||
$ sudo cp kata-linux-experimental-*/vmlinux /opt/kata/share/kata-containers/vmlinux.sgx
|
|
||||||
$ sudo sed -i 's|vmlinux.container|vmlinux.sgx|g' \
|
|
||||||
/opt/kata/share/defaults/kata-containers/configuration-clh.toml
|
|
||||||
```
|
|
||||||
|
|
||||||
### Kata Containers Configuration
|
### Kata Containers Configuration
|
||||||
|
|
||||||
@ -48,6 +35,8 @@ to the `sandbox` are: `["io.katacontainers.*", "sgx.intel.com/epc"]`.
|
|||||||
|
|
||||||
With the following sample job deployed using `kubectl apply -f`:
|
With the following sample job deployed using `kubectl apply -f`:
|
||||||
|
|
||||||
|
> Note: Change the `runtimeClassName` option accordingly, only `kata-clh` and `kata-qemu` support Intel® SGX.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: batch/v1
|
apiVersion: batch/v1
|
||||||
kind: Job
|
kind: Job
|
||||||
|
Loading…
Reference in New Issue
Block a user