Skip to content

feat: add nvidia gpu support to coco pattern#82

Merged
butler54 merged 7 commits intovalidatedpatterns:mainfrom
butler54:feat/nvidia-confidential-gpu
May 6, 2026
Merged

feat: add nvidia gpu support to coco pattern#82
butler54 merged 7 commits intovalidatedpatterns:mainfrom
butler54:feat/nvidia-confidential-gpu

Conversation

@butler54
Copy link
Copy Markdown
Collaborator

No description provided.

@butler54 butler54 requested a review from a team April 24, 2026 05:44
butler54 and others added 6 commits May 6, 2026 09:44
…book

Add nvidia-gpu chart (ClusterPolicy, IOMMU MachineConfig) and
gpu-workload chart (vectorAdd deployment for CC GPU verification).
Add reconcile-kataconfig-gpu.yaml ansible playbook that triggers
KataConfig re-reconciliation when GPU nodes are detected but the
kata-cc-nvidia-gpu RuntimeClass has not yet been created.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Add kata-cc-nvidia-gpu to the runtime class list in the initdata
injection policy so GPU workloads receive cc_init_data annotations.
Add gpu-workload to workloadNamespaces for Kyverno policy scope.
Add LAB.md to .gitignore.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
New values file for bare metal clusters with NVIDIA H100 GPUs.
Extends baremetal topology with GPU operator subscription, nvidia-gpu
chart, gpu-workload deployment, and reconcile-kataconfig-gpu job.
Uses released trustee chart 0.3.* with kbs.gpu.enabled.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
The default 128Mi limit causes OOMKill when processing policies
across many namespaces on bare metal clusters.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
The previous code always hashed the literal strings 'usertoken' and
'admintoken' regardless of whether the user had changed the token
files. Now reads the actual file content for hashing.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Document the new GPU topology and provide setup instructions.
Clarify that non-GPU systems should use the baremetal topology.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@butler54 butler54 force-pushed the feat/nvidia-confidential-gpu branch from ee6ce9a to b71c9db Compare May 6, 2026 00:46
Update version section from 4.* to 5.* with release history.
Document bare metal (v5.1) and GPU (v5.2) support milestones.
Note that bare metal is currently tested on SNO only.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@butler54 butler54 merged commit 8487fb1 into validatedpatterns:main May 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant