-
Notifications
You must be signed in to change notification settings - Fork 53
coco docs: improvements for version pinning and minor fixes #494
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
a393e68
0843b39
16e13c7
1d1cb5b
d79e107
1ba1e21
4bcfd94
0dce299
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -114,12 +114,12 @@ Step 1: Install Trustee with Docker Compose | |
| ------------------------------------------- | ||
|
|
||
| Installing Trustee with Docker Compose is the recommended install path. | ||
| Clone the upstream Trustee repository. | ||
| Clone the upstream Trustee repository at ${trustee_version}. | ||
| The repository ships with a ``docker-compose.yml`` that wires KBS, the Attestation Service, and the Reference Value Provider Service together. | ||
|
|
||
| .. code-block:: console | ||
|
|
||
| $ git clone https://github.com/confidential-containers/trustee.git && cd trustee | ||
| $ git clone --branch ${trustee_version} --depth 1 https://github.com/confidential-containers/trustee.git && cd trustee | ||
|
manuelh-dev marked this conversation as resolved.
|
||
|
|
||
| Start the Trustee containers in the background. | ||
|
|
||
|
|
@@ -142,6 +142,22 @@ Start the Trustee containers in the background. | |
| On first run, ``docker compose up -d`` pulls the KBS, AS, and RVPS images before starting them. | ||
| This step can take several minutes. The command returns after the containers start. The services may need an additional few seconds to become ready to accept requests. | ||
|
|
||
| .. note:: | ||
|
|
||
| The Trustee ${trustee_version} `docker-compose.yml <https://github.com/confidential-containers/trustee/blob/${trustee_version}/docker-compose.yml>`_ still references ``:latest`` images for KBS, AS, and RVPS. | ||
| While cloning that tag pins the compose configuration to a released version, ``docker compose up -d`` still pulls whatever ``:latest`` resolves to at that time. | ||
|
manuelh-dev marked this conversation as resolved.
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's add some guidance for how to patch the image. We will be able to remove this in the future when we change the Trustee release process.
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. @fitzthum ptal, updated with new concrete pins for the time being - in a future time, we can just remove the There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Looks good. We will be able to do this a bit more cleanly when we switch to Helm chart and then before too long we won't need to do it at all. |
||
| ``:latest`` does not match Trustee ${trustee_version}. | ||
| For a reproducible backend that matches this architecture, replace the three ``image:`` lines before you run ``docker compose up -d``: | ||
|
|
||
| * KBS: ``ghcr.io/confidential-containers/staged-images/kbs-grpc-as:${trustee_image_tag}`` | ||
| * AS: ``ghcr.io/confidential-containers/staged-images/coco-as-grpc:${trustee_image_tag}`` | ||
| * RVPS: ``ghcr.io/confidential-containers/staged-images/rvps:${trustee_image_tag}`` | ||
|
|
||
| Those tags are the Trustee ${trustee_version} commit, the same commit as the ``kbs-client`` artifact in the next step. | ||
| The GHCR registry does not publish a ``${trustee_version}`` tag for these images. | ||
| Equivalent digest pins are ``kbs-grpc-as@${trustee_kbs_image_digest}``, ``coco-as-grpc@${trustee_as_image_digest}``, and ``rvps@${trustee_rvps_image_digest}``. | ||
| This edit is unnecessary after Trustee starts pinning images in the release compose file. | ||
|
|
||
| For details on optional configuration such as the admin keypair, debug logging, and per-service config files, refer to the upstream `Install Trustee in Docker <https://confidentialcontainers.org/docs/attestation/installation/docker/>`_ guide. | ||
|
|
||
|
|
||
|
|
@@ -184,21 +200,21 @@ Step 3: Install the KBS Client Tool | |
|
|
||
| The KBS client tool, ``kbs-client``, is distributed as a container artifact in the Confidential Containers GitHub Container Registry. | ||
| This tool is mainly used for configuring Trustee. | ||
|
|
||
| Pull the ``kbs-client`` artifact into the current directory with ORAS. | ||
| The registry does not publish a ``${trustee_version}`` tag for this artifact. | ||
|
manuelh-dev marked this conversation as resolved.
|
||
| Pull the ``sample_only`` build for the Trustee ${trustee_version} commit on ``x86_64``. | ||
|
|
||
| .. code-block:: console | ||
|
|
||
| $ oras pull ghcr.io/confidential-containers/staged-images/kbs-client:latest | ||
| $ oras pull ghcr.io/confidential-containers/staged-images/kbs-client:${kbs_client_tag} | ||
|
|
||
| *Example Output:* | ||
|
|
||
| .. code-block:: output | ||
|
|
||
| ✓ Pulled kbs-client 12.3/12.3 MB 100.00% | ||
| ✓ Pulled application/vnd.oci.image.manifest.v1+json 533/533 B 100.00% | ||
| Pulled [registry] ghcr.io/confidential-containers/staged-images/kbs-client:latest | ||
| Digest: sha256:a2a48a7cea6dc5d1bad3baea15f4162835e1262eb74fdf4847a6382d09dc5caa | ||
| Downloading 5148271f5a55 kbs-client | ||
| Downloaded 5148271f5a55 kbs-client | ||
| Pulled [registry] ghcr.io/confidential-containers/staged-images/kbs-client:${kbs_client_tag} | ||
| Digest: sha256:429be62c527e766a9854f9dac37f878010069c4aa6745d3d555d2bf393b9e82e | ||
|
|
||
| Confirm the ``kbs-client`` binary was extracted to the current directory. | ||
|
|
||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.