We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 4457085 commit d8f7bc0Copy full SHA for d8f7bc0
config/peerpods/podvm/lib.sh
@@ -195,6 +195,12 @@ function prepare_source_code() {
195
sed -i '/exit 0/ifips-mode-setup --enable' "${podvm_dir}"/qcow2/misc-settings.sh ||
196
error_exit "Failed to enable fips mode"
197
fi
198
+
199
+ if [[ "$CONFIDENTIAL_COMPUTE_ENABLED" == "yes" ]]; then
200
+ sed 's/default SetPolicyRequest := true/default SetPolicyRequest := false/; s/default ExecProcessRequest := true/default ExecProcessRequest := false/' \
201
+ "${podvm_dir}"/files/etc/kata-opa/default-policy.rego > "${podvm_dir}"/files/etc/kata-opa/coco-default-policy.rego
202
+ ln -sf "${podvm_dir}"/files/etc/kata-opa/coco-default-policy.rego "${podvm_dir}"/files/etc/kata-opa/default-policy.rego
203
+ fi
204
}
205
206
# Download and extract pause container image
0 commit comments