1584 Commits

Author SHA1 Message Date
Nils Hanke
1caf9fb9b9 Test patched Kernel 6.1 2022-12-27 21:26:15 +01:00
Nils Hanke
654af4defc Use upstream v6.0.0 kernel with random Microsoft patches 2022-12-27 17:18:31 +01:00
Nils Hanke
bebd4440c6 Use custom Azure 5.4 CVM kernel with Wireguard patched in 2022-12-22 13:42:13 +01:00
Nils Hanke
59d3d79ab5 Downsize partitions for hopefully faster pipeline 2022-12-22 13:40:07 +01:00
Nils Hanke
57432dc27a Revert "Cilium: Enable wireguard-go fallback & mount TUN device from host"
This reverts commit 08baebbe627c0b63ab4d62baf540ad4563562001.
2022-12-22 13:39:39 +01:00
Nils Hanke
fcea00331a Revert "Disable encryption"
This reverts commit 9bfdce096c27ca11b7db2a7224e1eabfcbdf84cc.
2022-12-22 13:39:32 +01:00
Nils Hanke
9bfdce096c Disable encryption 2022-12-21 19:48:13 +01:00
Nils Hanke
08baebbe62 Cilium: Enable wireguard-go fallback & mount TUN device from host
(Required for Kernel 5.4, since Wireguard is only available in-kernel
since v5.6)
2022-12-21 19:10:22 +01:00
Nils Hanke
f3cc806118 Go to Ubuntu-azure-cvm-5.4.0-1080.83+cvm1 2022-12-21 14:09:03 +01:00
Nils Hanke
0ec315fd48 Disable AppArmor 2022-12-20 19:39:19 +01:00
Nils Hanke
5211c44aa2 Useless commit to bump git hash to avoid image collisions 2022-12-20 15:56:30 +01:00
Nils Hanke
db70048808 Increase storage because we're lazy 2022-12-20 14:43:02 +01:00
Nils Hanke
6458d77f1e Bump 2022-12-20 13:56:09 +01:00
Nils Hanke
45df929c8a Test: Use custom built kernel from Azure Ubuntu 2022-12-20 13:31:24 +01:00
Malte Poll
758d9dcea7 Release CLI: Fix upload path v2.3.0 2022-12-12 16:44:16 +01:00
Malte Poll
e78d2dbf8a Embed measurements for v2.3.0 2022-12-12 15:56:50 +01:00
Malte Poll
46a1ebf8d3 Match pki set and key 2022-12-12 15:56:33 +01:00
Malte Poll
191e52a692 OS build pipeline: Correctly choose PKI set 2022-12-12 15:56:30 +01:00
Malte Poll
8a4ecff7f3 Expand PCR selection on AWS 2022-12-12 14:06:19 +01:00
Malte Poll
c27be1a6cc Fix OS image build pipeline for releases 2022-12-12 10:28:43 +01:00
Malte Poll
ce2b3f37fb Bump version to v2.3.0 2022-12-12 09:52:56 +01:00
Malte Poll
ce1c7f5936 Update CHANGELOG for v2.3.0 2022-12-12 09:51:44 +01:00
renovate[bot]
5eae12778a
Update Constellation containers (#777)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2022-12-09 18:45:09 +01:00
3u13r
c993cd6800
join: synchronize control plane joining (#776)
* join: synchronize control plane joining
2022-12-09 18:30:20 +01:00
renovate[bot]
012f739c67
Update Constellation containers (#759)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 16:32:58 +01:00
renovate[bot]
34f2d00766
Update module libvirt.org/go/libvirt to v1.8010.0 (#774)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 16:01:26 +01:00
renovate[bot]
0655c05d79
Update module github.com/sigstore/sigstore to v1.5.0 (#773)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 15:49:50 +01:00
renovate[bot]
1daae77189
Update AWS SDK (#769)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 15:28:27 +01:00
renovate[bot]
85f9d62a9f
Update Terraform azurerm to v3.35.0 (#768)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 15:21:13 +01:00
renovate[bot]
4ec2fceeef
Update Terraform aws to v4.46.0 (#767)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 15:13:09 +01:00
Malte Poll
3c5fa3175a
Fix image build pipeline: Use braces to group complex expressions (#770) 2022-12-09 14:48:52 +01:00
renovate[bot]
4e6f88c355 Update gcr.io/kubebuilder/kube-rbac-proxy Docker tag to v0.13.1 2022-12-09 14:30:39 +01:00
Malte Poll
4a8ebfd921 OS images: use "ref", "stream" and "version"
Switch azure default region to west us
Update find-image script to work with new API spec
Add version for every os image build
generate measurements: Use new API paths
CLI: config fetch measurements: Use image short versions to fetch measurements
CLI: allows shortnames to specify image in config
Image build pipeline: Change paths to contain "ref" and "stream"
2022-12-09 13:37:43 +01:00
Paul Meyer
4795fe9695 hack: create latest endpoint in add-version script
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 13:37:43 +01:00
Paul Meyer
f23a2fe073 hack: implement new api for add-version script
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 13:37:43 +01:00
Otto Bittner
e461b6385a
Document cert-manager installation. (#752) 2022-12-09 13:28:29 +01:00
Paul Meyer
d3873988c9 ci: fix download scripts for serial logs
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 13:22:45 +01:00
Paul Meyer
9e9468ff44 ci: add csp name to serial log artifact name
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 13:22:45 +01:00
Malte Poll
53576d63a0
Downgrade GCP kernel to 5.19.17-300 (#763) 2022-12-09 13:20:00 +01:00
renovate[bot]
72ba97efcc
Update K8s constrained versions (#762)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 13:17:55 +01:00
renovate[bot]
e371e4499f
Update GitHub action dependencies (#765)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 11:10:23 +01:00
renovate[bot]
488d9369d7
Update ubuntu:22.04 Docker digest to 965fbca (#764)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 11:04:14 +01:00
Paul Meyer
4c2ffe7905
Update Google SDK (#760)
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-09 10:59:18 +01:00
Daniel Weiße
7e50f871bf
Update CSI installation instructions in versioned docs (#741)
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
2022-12-09 08:48:33 +01:00
Daniel Weiße
d356a40bc3
Pull in CSI chart from release tag (#757)
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
2022-12-09 08:32:58 +01:00
Paul Meyer
1709da0085 image: fix script for PKI generation
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 18:07:54 +01:00
renovate[bot]
9d0d561726
Update Terraform google to v4.45.0 (#742)
Co-authored-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 15:59:15 +01:00
Paul Meyer
9b1551e76a dependencies: migrate go-genproto to google-cloud-go
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 13:27:15 +01:00
Paul Meyer
eff3dd8aea dependencies: upgrade containerd module
Fixes CVE-2022-23471.

Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 13:27:15 +01:00
Paul Meyer
24f6c3807b ci: no link checking on main
Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
2022-12-08 11:42:03 +01:00