Skip to content

Commit ea725a5

Browse files
authored
Merge pull request #55 from dongx1x/configfs-tsm
2 parents 9e111da + c580dff commit ea725a5

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

deployment/kubernetes/manifests/ccnp-server-deployment.yaml

+10
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,10 @@ spec:
2929
resources:
3030
limits:
3131
tdx.intel.com/tdx-guest: 1
32+
securityContext:
33+
privileged: true
34+
runAsGroup: 0
35+
runAsUser: 0
3236
volumeMounts:
3337
- name: proc
3438
mountPath: /proc
@@ -40,6 +44,8 @@ spec:
4044
mountPath: /run/kernel/security/
4145
- name: vsock-port
4246
mountPath: /etc/tdx-attest.conf
47+
- name: configfs
48+
mountPath: /sys/kernel/config/
4349
volumes:
4450
- name: proc
4551
hostPath:
@@ -61,5 +67,9 @@ spec:
6167
hostPath:
6268
path: /etc/tdx-attest.conf
6369
type: File
70+
- name: configfs
71+
hostPath:
72+
path: /sys/kernel/config/
73+
type: Directory
6474
nodeSelector:
6575
intel.feature.node.kubernetes.io/tdx-guest: "enabled"

0 commit comments

Comments
 (0)