Commit a068079
committed
Run trustee as non-privileged container
1) the paths /opt/confidential-container and
/opt/confidential-container/kbs/repository/default are mounted
as RW volumes in memory to allow trustee components
to have full access to the filesystem
2) some refactoring around the volumes creation
Signed-off-by: Leonardo Milleri <[email protected]>1 parent c1c0c3f commit a068079
File tree
4 files changed
+415
-349
lines changed- config/samples/all-in-one
- internal/controller
4 files changed
+415
-349
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
35 | 35 | | |
36 | 36 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
42 | 53 | | |
43 | | - | |
| 54 | + | |
44 | 55 | | |
45 | 56 | | |
46 | 57 | | |
| |||
52 | 63 | | |
53 | 64 | | |
54 | 65 | | |
55 | | - | |
| 66 | + | |
56 | 67 | | |
57 | 68 | | |
58 | 69 | | |
| |||
0 commit comments