From a393e684a14d9cb8d2a22824ffab8eb06aec8ddc Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 13:37:49 -0700 Subject: [PATCH 1/8] coco docs: pin genpolicy to Kata 4.1.0 Recommend Kata Containers genpolicy 4.1.0 for agent security policy generation, and point downloads and the README at that release instead of main or an unnamed matching Kata tag. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/configure-workloads.rst | 9 ++++++--- confidential-containers/supported-platforms.rst | 7 ++++--- repo.toml | 2 +- 3 files changed, 11 insertions(+), 7 deletions(-) diff --git a/confidential-containers/configure-workloads.rst b/confidential-containers/configure-workloads.rst index 5ea87d8d4..25980dcc7 100644 --- a/confidential-containers/configure-workloads.rst +++ b/confidential-containers/configure-workloads.rst @@ -335,11 +335,14 @@ Do not treat that YAML as a production template. The Kata Containers ``genpolicy`` tool reads your Kubernetes YAML, infers the intended Agent API calls, encodes the policy in base64, and appends it as an annotation on the same file. +The Kata agent in the guest receives that annotation. +Use ``genpolicy`` ${genpolicy_version}, which is the version this architecture validates with that agent. +Refer to :ref:`Supported Software Components ` for the component matrix. -#. Download ``genpolicy`` from the latest Kata Containers release that is compatible with this - reference architecture. +#. Download ``genpolicy`` ${genpolicy_version} from the + `Kata Containers ${genpolicy_version} release `_. For usage details, refer to the - `Agent Policy generation tool `_ + `Agent Policy generation tool `_ documentation. #. Run ``genpolicy`` against the manifest to deploy: diff --git a/confidential-containers/supported-platforms.rst b/confidential-containers/supported-platforms.rst index 1882b61cf..9d37bd1f8 100644 --- a/confidential-containers/supported-platforms.rst +++ b/confidential-containers/supported-platforms.rst @@ -183,9 +183,10 @@ The following components and interfaces are not installed by the :doc:`Quickstar - 0.1.8 - Optional for Kata Containers upgrades and day-two lifecycle management. - Install separately by following the upstream Kata Lifecycle Manager documentation. - * - `Kata Containers genpolicy `__ - - ${kata_version} + * - `Kata Containers genpolicy `__ + - ${genpolicy_version} - Used to generate an agent security policy for attested production workloads. - - Download separately from the corresponding Kata Containers release. + Refer to :ref:`Attach a Kata Agent Security Policy `. + - Download ``genpolicy`` ${genpolicy_version} from the `Kata Containers ${genpolicy_version} release `__. Users may leverage `Red Hat OpenShift Sandboxed Containers `__ to deploy Confidential Containers. diff --git a/repo.toml b/repo.toml index e90ea2a7b..f5708c584 100644 --- a/repo.toml +++ b/repo.toml @@ -215,7 +215,7 @@ docs_root = "${root}/confidential-containers" project = "confidential-containers" name = "NVIDIA Confidential Containers Architecture" version = "1.1.0" -source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3" } +source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0" } copyright_start = 2020 [repo_docs.projects.confidential-containers.builds.linkcheck] From 0843b3915260a29adfa56eeca25ddea0f6af1639 Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 13:50:18 -0700 Subject: [PATCH 2/8] coco docs: list NVRC and guest GPU driver Record NVRC v0.1.5 and NVIDIA GPU driver 595.58.03 in the distroless guest OS cell so the platforms matrix names the payload this architecture validates. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/supported-platforms.rst | 3 ++- repo.toml | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/confidential-containers/supported-platforms.rst b/confidential-containers/supported-platforms.rst index 9d37bd1f8..f2a5e0f45 100644 --- a/confidential-containers/supported-platforms.rst +++ b/confidential-containers/supported-platforms.rst @@ -154,7 +154,8 @@ You do not supply or install these artifacts individually. * - Artifact - Release/Version * - Guest OS - - Distroless + - Distroless, with `NVRC ${nvrc_version} `__ + and NVIDIA GPU driver ${guest_nvidia_driver_version} * - Guest kernel - 6.18.5 * - `OVMF `__ diff --git a/repo.toml b/repo.toml index f5708c584..f67893611 100644 --- a/repo.toml +++ b/repo.toml @@ -215,7 +215,7 @@ docs_root = "${root}/confidential-containers" project = "confidential-containers" name = "NVIDIA Confidential Containers Architecture" version = "1.1.0" -source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0" } +source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0", nvrc_version = "v0.1.5", guest_nvidia_driver_version = "595.58.03" } copyright_start = 2020 [repo_docs.projects.confidential-containers.builds.linkcheck] From 16e13c7e07e1524010a4cb67980ac3e41a7f5034 Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 13:50:50 -0700 Subject: [PATCH 3/8] coco docs: refresh guest kernel and QEMU pins Align the guest kernel and QEMU versions with Kata Containers 4.1.0 versions.yaml (6.18.35 and 11.0.1 plus GPU patches). Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/supported-platforms.rst | 4 ++-- repo.toml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/confidential-containers/supported-platforms.rst b/confidential-containers/supported-platforms.rst index f2a5e0f45..9f219014a 100644 --- a/confidential-containers/supported-platforms.rst +++ b/confidential-containers/supported-platforms.rst @@ -157,11 +157,11 @@ You do not supply or install these artifacts individually. - Distroless, with `NVRC ${nvrc_version} `__ and NVIDIA GPU driver ${guest_nvidia_driver_version} * - Guest kernel - - 6.18.5 + - ${guest_kernel_version} * - `OVMF `__ - edk2-stable202511 * - `QEMU `__ - - 10.1 \+ Patches + - ${qemu_version} \+ Patches Separately Deployed Components and Interfaces ============================================= diff --git a/repo.toml b/repo.toml index f67893611..04caf753f 100644 --- a/repo.toml +++ b/repo.toml @@ -215,7 +215,7 @@ docs_root = "${root}/confidential-containers" project = "confidential-containers" name = "NVIDIA Confidential Containers Architecture" version = "1.1.0" -source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0", nvrc_version = "v0.1.5", guest_nvidia_driver_version = "595.58.03" } +source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0", nvrc_version = "v0.1.5", guest_nvidia_driver_version = "595.58.03", guest_kernel_version = "6.18.35", qemu_version = "11.0.1" } copyright_start = 2020 [repo_docs.projects.confidential-containers.builds.linkcheck] From 1d1cb5bd6b8a2a75fdd3e0bba1a5ccf51c3aaad9 Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 14:24:10 -0700 Subject: [PATCH 4/8] coco docs: substitute GPU Operator version in quickstart Use gpu_operator_version in the Helm install command so the quickstart pin stays in sync with the detailed install page. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/install-quickstart.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/confidential-containers/install-quickstart.rst b/confidential-containers/install-quickstart.rst index 2999be8f7..cc7d01574 100644 --- a/confidential-containers/install-quickstart.rst +++ b/confidential-containers/install-quickstart.rst @@ -169,7 +169,7 @@ Install the NVIDIA GPU Operator --set sandboxWorkloads.mode=kata \ --set nfd.enabled=true \ --set nfd.nodefeaturerules=true \ - --version=v26.3.1 + --version=${gpu_operator_version} *Example Output:* From d79e107c6104da5232396e18cbeffa552e54c128 Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 14:25:50 -0700 Subject: [PATCH 5/8] coco docs: align kata-deploy wait and NFD notes Add --wait to the detailed install command so Helm blocks as described, and attribute nfd.enabled=false to the values file. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/confidential-containers-deploy.rst | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/confidential-containers/confidential-containers-deploy.rst b/confidential-containers/confidential-containers-deploy.rst index 4710012e1..d268b2086 100644 --- a/confidential-containers/confidential-containers-deploy.rst +++ b/confidential-containers/confidential-containers-deploy.rst @@ -165,6 +165,7 @@ The minimum required version is ${kata_version}. $ helm install kata-deploy "${CHART}" \ --namespace kata-system --create-namespace \ -f kata-nvidia-gpu-values.yaml \ + --wait --timeout 10m \ --version "${VERSION}" *Example Output immediately after running the command:* @@ -201,7 +202,7 @@ The minimum required version is ${kata_version}. .. note:: Both ``kata-deploy`` and the GPU Operator deploy Node Feature Discovery (NFD) by default. - The install command includes ``--set nfd.enabled=false`` to prevent ``kata-deploy`` from deploying NFD. + The values file sets ``nfd.enabled: false`` to prevent ``kata-deploy`` from deploying NFD. The GPU Operator will deploy and manage NFD in the next step. #. Verify that the ``kata-deploy`` pod is running: From 1ba1e214b5610fcd48324d6151d5472e2ce6880b Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Mon, 14 Sep 2026 16:00:24 -0700 Subject: [PATCH 6/8] coco docs: pin Trustee and guest-components Replace the KBS protocol 0.4.0 matrix row with Trustee v0.21.0, name guest-components v0.21.0 in the distroless guest, and pin the attestation quickstart clone, Compose images, and kbs-client to that release. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/attestation.rst | 34 ++++++++++++++----- .../supported-platforms.rst | 14 ++++---- repo.toml | 2 +- 3 files changed, 34 insertions(+), 16 deletions(-) diff --git a/confidential-containers/attestation.rst b/confidential-containers/attestation.rst index 2c3b43164..61a36da1c 100644 --- a/confidential-containers/attestation.rst +++ b/confidential-containers/attestation.rst @@ -114,12 +114,12 @@ Step 1: Install Trustee with Docker Compose ------------------------------------------- Installing Trustee with Docker Compose is the recommended install path. -Clone the upstream Trustee repository. +Clone the upstream Trustee repository at ${trustee_version}. The repository ships with a ``docker-compose.yml`` that wires KBS, the Attestation Service, and the Reference Value Provider Service together. .. code-block:: console - $ git clone https://github.com/confidential-containers/trustee.git && cd trustee + $ git clone --branch ${trustee_version} --depth 1 https://github.com/confidential-containers/trustee.git && cd trustee Start the Trustee containers in the background. @@ -142,6 +142,22 @@ Start the Trustee containers in the background. On first run, ``docker compose up -d`` pulls the KBS, AS, and RVPS images before starting them. This step can take several minutes. The command returns after the containers start. The services may need an additional few seconds to become ready to accept requests. +.. note:: + + The Trustee ${trustee_version} `docker-compose.yml `_ still references ``:latest`` images for KBS, AS, and RVPS. + While cloning that tag pins the compose configuration to a released version, ``docker compose up -d`` still pulls whatever ``:latest`` resolves to at that time. + ``:latest`` does not match Trustee ${trustee_version}. + For a reproducible backend that matches this architecture, replace the three ``image:`` lines before you run ``docker compose up -d``: + + * KBS: ``ghcr.io/confidential-containers/staged-images/kbs-grpc-as:${trustee_image_tag}`` + * AS: ``ghcr.io/confidential-containers/staged-images/coco-as-grpc:${trustee_image_tag}`` + * RVPS: ``ghcr.io/confidential-containers/staged-images/rvps:${trustee_image_tag}`` + + Those tags are the Trustee ${trustee_version} commit, the same commit as the ``kbs-client`` artifact in the next step. + The GHCR registry does not publish a ``${trustee_version}`` tag for these images. + Equivalent digest pins are ``kbs-grpc-as@${trustee_kbs_image_digest}``, ``coco-as-grpc@${trustee_as_image_digest}``, and ``rvps@${trustee_rvps_image_digest}``. + This edit is unnecessary after Trustee starts pinning images in the release compose file. + For details on optional configuration such as the admin keypair, debug logging, and per-service config files, refer to the upstream `Install Trustee in Docker `_ guide. @@ -184,21 +200,21 @@ Step 3: Install the KBS Client Tool The KBS client tool, ``kbs-client``, is distributed as a container artifact in the Confidential Containers GitHub Container Registry. This tool is mainly used for configuring Trustee. - -Pull the ``kbs-client`` artifact into the current directory with ORAS. +The registry does not publish a ``${trustee_version}`` tag for this artifact. +Pull the ``sample_only`` build for the Trustee ${trustee_version} commit on ``x86_64``. .. code-block:: console - $ oras pull ghcr.io/confidential-containers/staged-images/kbs-client:latest + $ oras pull ghcr.io/confidential-containers/staged-images/kbs-client:${kbs_client_tag} *Example Output:* .. code-block:: output - ✓ Pulled kbs-client 12.3/12.3 MB 100.00% - ✓ Pulled application/vnd.oci.image.manifest.v1+json 533/533 B 100.00% - Pulled [registry] ghcr.io/confidential-containers/staged-images/kbs-client:latest - Digest: sha256:a2a48a7cea6dc5d1bad3baea15f4162835e1262eb74fdf4847a6382d09dc5caa + Downloading 5148271f5a55 kbs-client + Downloaded 5148271f5a55 kbs-client + Pulled [registry] ghcr.io/confidential-containers/staged-images/kbs-client:${kbs_client_tag} + Digest: sha256:429be62c527e766a9854f9dac37f878010069c4aa6745d3d555d2bf393b9e82e Confirm the ``kbs-client`` binary was extracted to the current directory. diff --git a/confidential-containers/supported-platforms.rst b/confidential-containers/supported-platforms.rst index 9f219014a..3b4f4489b 100644 --- a/confidential-containers/supported-platforms.rst +++ b/confidential-containers/supported-platforms.rst @@ -154,8 +154,9 @@ You do not supply or install these artifacts individually. * - Artifact - Release/Version * - Guest OS - - Distroless, with `NVRC ${nvrc_version} `__ - and NVIDIA GPU driver ${guest_nvidia_driver_version} + - Distroless, with `NVRC ${nvrc_version} `__, + NVIDIA GPU driver ${guest_nvidia_driver_version}, and + `guest-components ${guest_components_version} `__ artifacts. * - Guest kernel - ${guest_kernel_version} * - `OVMF `__ @@ -175,10 +176,11 @@ The following components and interfaces are not installed by the :doc:`Quickstar - Version - When It Is Needed - How It Is Provided - * - `Key Broker Service (KBS) protocol `__ - - 0.4.0 - - Required for Trustee-based attestation and secret or key release. - - The :doc:`Attestation ` quickstart installs a local evaluation Trustee. + * - `Trustee `__ + - ${trustee_version} + - Required for attestation and secret or key release. + This architecture validates Trustee ${trustee_version} with guest-components ${guest_components_version} in the Kata guest. + - The :doc:`Attestation ` quickstart installs a local evaluation Trustee ${trustee_version}. Deploy a production Trustee separately by following the upstream Confidential Containers documentation. * - `Kata Lifecycle Manager `__ - 0.1.8 diff --git a/repo.toml b/repo.toml index 04caf753f..fb1258d0d 100644 --- a/repo.toml +++ b/repo.toml @@ -215,7 +215,7 @@ docs_root = "${root}/confidential-containers" project = "confidential-containers" name = "NVIDIA Confidential Containers Architecture" version = "1.1.0" -source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0", nvrc_version = "v0.1.5", guest_nvidia_driver_version = "595.58.03", guest_kernel_version = "6.18.35", qemu_version = "11.0.1" } +source_substitutions = { kata_version = "4.0.0", gpu_operator_version = "v26.3.1", gpu_operator_minor_version = "26.3", genpolicy_version = "4.1.0", nvrc_version = "v0.1.5", guest_nvidia_driver_version = "595.58.03", guest_kernel_version = "6.18.35", qemu_version = "11.0.1", trustee_version = "v0.21.0", guest_components_version = "v0.21.0", trustee_image_tag = "258ea4acb7b9bd865fce5c63a539f2120dba8298", kbs_client_tag = "sample_only-258ea4acb7b9bd865fce5c63a539f2120dba8298-x86_64", trustee_kbs_image_digest = "sha256:873a1e1704965d1325b70fdf31335cc8d9c95acab4f003b0f3ece675b3584dd8", trustee_as_image_digest = "sha256:5319dcb609ed1d61876491bb43be1e03838f29eab7cea5673c7979892dc8015a", trustee_rvps_image_digest = "sha256:185cdc6754e544de3068a4f9c25733d62e7e6cfb8464da9f2de2ac490573b509" } copyright_start = 2020 [repo_docs.projects.confidential-containers.builds.linkcheck] From 4bcfd94976e134f4d2bc8cea5b551c701d74ebda Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Wed, 16 Sep 2026 13:03:08 -0700 Subject: [PATCH 7/8] docs: correct kata-deploy NFD Helm settings Use the kata-deploy node-feature-discovery chart key in the CoCo sample values file and the GPU Operator Kata install command. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- .../confidential-containers-deploy.rst | 4 ++-- .../samples/kata-nvidia-gpu-values.yaml | 8 ++++---- gpu-operator/deploy-kata-containers.rst | 6 +++--- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/confidential-containers/confidential-containers-deploy.rst b/confidential-containers/confidential-containers-deploy.rst index d268b2086..89b65098b 100644 --- a/confidential-containers/confidential-containers-deploy.rst +++ b/confidential-containers/confidential-containers-deploy.rst @@ -201,8 +201,8 @@ The minimum required version is ${kata_version}. .. note:: - Both ``kata-deploy`` and the GPU Operator deploy Node Feature Discovery (NFD) by default. - The values file sets ``nfd.enabled: false`` to prevent ``kata-deploy`` from deploying NFD. + Both ``kata-deploy`` and the GPU Operator can deploy Node Feature Discovery (NFD). + The values file disables the NFD deployment by ``kata-deploy``. The GPU Operator will deploy and manage NFD in the next step. #. Verify that the ``kata-deploy`` pod is running: diff --git a/confidential-containers/samples/kata-nvidia-gpu-values.yaml b/confidential-containers/samples/kata-nvidia-gpu-values.yaml index 6340a6c4f..626c6df9c 100644 --- a/confidential-containers/samples/kata-nvidia-gpu-values.yaml +++ b/confidential-containers/samples/kata-nvidia-gpu-values.yaml @@ -7,11 +7,11 @@ debug: false deploymentMode: daemonset # Disable Node Feature Discovery (NFD) deployment by kata-deploy. -# Both kata-deploy and the GPU Operator deploy NFD by default. This -# reference architecture relies on the NFD instance that the GPU Operator -# deploys and manages, so the kata-deploy NFD is turned off to avoid a +# Both kata-deploy and the GPU Operator can deploy NFD. This reference +# architecture relies on the NFD instance that the GPU Operator deploys +# and manages, so the kata-deploy NFD subchart is turned off to avoid a # duplicate, conflicting deployment. -nfd: +node-feature-discovery: enabled: false # Install the nydus snapshotter on each node alongside containerd. diff --git a/gpu-operator/deploy-kata-containers.rst b/gpu-operator/deploy-kata-containers.rst index 9c17adde1..02b12b431 100644 --- a/gpu-operator/deploy-kata-containers.rst +++ b/gpu-operator/deploy-kata-containers.rst @@ -321,7 +321,7 @@ The minimum required version is ${kata_version}. $ helm install kata-deploy "${CHART}" \ --namespace kata-system --create-namespace \ - --set nfd.enabled=false \ + --set node-feature-discovery.enabled=false \ -f kata-nvidia-gpu-values.yaml \ --version "${VERSION}" @@ -341,8 +341,8 @@ The minimum required version is ${kata_version}. .. note:: - Both ``kata-deploy`` and the GPU Operator deploy Node Feature Discovery (NFD) by default. - The install command includes ``--set nfd.enabled=false`` to prevent ``kata-deploy`` from deploying NFD. + Both ``kata-deploy`` and the GPU Operator can deploy Node Feature Discovery (NFD). + The install command disables the NFD deployment by ``kata-deploy``. The GPU Operator will deploy and manage NFD in the next step. .. note:: From 0dce2991641fb5c204e4b19411b44656abe73188 Mon Sep 17 00:00:00 2001 From: Manuel Huber Date: Wed, 16 Sep 2026 12:01:36 -0700 Subject: [PATCH 8/8] docs: record post-release documentation updates Add a CoCo 1.1.0 section so published changes after the RA ship with a visible record, including #479, #480, and this PR. Record the kata-deploy NFD correction in GPU Operator 26.7.0. Document Trustee Compose image pins for the v0.21.0 commit. Signed-off-by: Manuel Huber Assisted-by: Cursor Grok 4.6 --- confidential-containers/release-notes.rst | 16 ++++++++++++++++ gpu-operator/release-notes.rst | 2 ++ 2 files changed, 18 insertions(+) diff --git a/confidential-containers/release-notes.rst b/confidential-containers/release-notes.rst index a15a3f66c..25dd66e60 100644 --- a/confidential-containers/release-notes.rst +++ b/confidential-containers/release-notes.rst @@ -64,6 +64,22 @@ Changes include: * Adds a readiness verification step using ``kubectl rollout status ds/kata-deploy``. This step relies on the readiness reporting in Kata Containers and lets you confirm that ``kata-deploy`` has finished extracting artifacts and restarting containerd on every node before continuing. +Post-Release Documentation Updates +---------------------------------- + +* Renamed the supported platforms page to :ref:`Supported Platforms and Software Components `. +* Documented attaching a Kata agent security policy for attested production workloads. + Refer to :ref:`Attach a Kata Agent Security Policy `. +* Split the software matrix into cluster prerequisites, Kata-provided guest and runtime artifacts, and separately deployed components. +* Recorded the distroless guest payload: NVRC, the NVIDIA GPU driver in the guest, and guest-components. +* Updated the guest kernel and QEMU versions to match the Kata Containers artifacts this architecture installs. +* Replaced the Key Broker Service protocol version with Trustee ${trustee_version} as the separately deployed attestation component. + The :doc:`Attestation ` quickstart clones that Trustee tag, documents Compose image pins for KBS, AS, and RVPS to that commit, and pulls the matching ``kbs-client`` artifact. +* Pinned ``genpolicy`` to ${genpolicy_version} and pointed the download and README links at that Kata Containers release. +* Restored ``--wait`` on the detailed ``kata-deploy`` install command and attributed the disabled NFD deployment to the values file. +* Corrected the NFD setting in :file:`samples/kata-nvidia-gpu-values.yaml`. + The sample used a key that the ``kata-deploy`` chart ignores, so the chart default kept NFD disabled instead of the sample. + ---- .. _coco-v1.0.0: diff --git a/gpu-operator/release-notes.rst b/gpu-operator/release-notes.rst index 1e6d9f471..319fec2db 100644 --- a/gpu-operator/release-notes.rst +++ b/gpu-operator/release-notes.rst @@ -204,6 +204,8 @@ Post-Release Documentation Updates * Added support for Kubernetes 1.36 for Canonical MicroK8s to the :ref:`bare-metal` table. * Added a brief explanation of the ``partitionN`` attribute to the :ref:`gpu-operator-kubevirt-dra` page. * Added support for Kubernetes 1.37 to the :ref:`bare-metal`, :ref:`cloud service providers `, and KubeVirt and OpenShift Virtualization tables. +* Corrected the ``kata-deploy`` Helm install on the :doc:`Kata Containers with GPU Operator ` page. + The previous ``--set`` used a GPU Operator chart key that the ``kata-deploy`` chart ignores. ----