Skip to content

feat: Update CoCo pattern docs for v4 GA (Trustee 1.0, OSC 1.11)#645

Merged
butler54 merged 4 commits intovalidatedpatterns:mainfrom
butler54:coco-100-update
May 7, 2026
Merged

feat: Update CoCo pattern docs for v4 GA (Trustee 1.0, OSC 1.11)#645
butler54 merged 4 commits intovalidatedpatterns:mainfrom
butler54:coco-100-update

Conversation

@butler54
Copy link
Copy Markdown
Contributor

Summary

  • Update confidential containers (CoCo) pattern documentation for v4 GA release
  • Upgrade component versions: Trustee 1.0, OpenShift Sandboxed Containers (OSC) 1.11, OCP 4.17+
  • Add multi-cluster deployment support with ACM/MultiClusterHub
  • Add new tested environments and version history page (coco-pattern-tested-environments.adoc)
  • Update Azure requirements with terminology and guidance fixes
  • Add missing technical terms to spellcheck wordlist

Test plan

  • Super-linter (slim-v7) passes locally — all GITLEAKS checks pass
  • Spellcheck passes for all CoCo pattern files with updated wordlist
  • CI super-linter (v8) passes on GitHub

🤖 Generated with Claude Code

Update confidential containers pattern documentation for the v4 GA release:
- Upgrade component versions: Trustee 1.0, OSC 1.11, OCP 4.17+
- Add multi-cluster deployment support with ACM/MCH
- Add new tested environments and version history page
- Update Azure requirements with terminology and guidance fixes
- Add missing technical terms to spellcheck wordlist

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@ocpdocs-previewbot
Copy link
Copy Markdown

ocpdocs-previewbot commented Feb 19, 2026

🤖 Thu May 07 04:28:37 - The preview is ready at:
https://645--patternsdocs-pr.netlify.app

@gaurav-nelson
Copy link
Copy Markdown
Collaborator

@butler54 Thank you for your PR.

  1. Is this ready for review and merge?

@beraldoleal
Copy link
Copy Markdown

@butler54 is there a way to see the preview? The link is broken.

Copy link
Copy Markdown

@beraldoleal beraldoleal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just minor comments.

Comment thread content/patterns/coco-pattern/coco-pattern-getting-started.adoc Outdated
Comment thread content/patterns/coco-pattern/_index.adoc Outdated
Major update to confidential containers pattern documentation:

Architecture updates:
- Update to v5 stack (OSC 1.12, Trustee 1.1, OCP 4.19.28+)
- Document Kyverno-based cc_init_data injection replacing MutatingAdmissionPolicy
- Add all four deployment topologies (simple, trusted-hub+spoke, baremetal, baremetal-gpu)
- Explicit callouts for Intel TDX and NVIDIA H100 confidential GPU support
- Document AMD SEV-SNP support (with note about future enhancements)

New content:
- Bare metal deployment instructions for Intel TDX and AMD SEV-SNP
- GPU deployment guide for NVIDIA H100 confidential GPUs
- Comprehensive troubleshooting page with problem/solution format
- Four mermaid diagrams (architecture, Kyverno flow, bare metal components, attestation)

Fixes:
- Fix capitalization: "sandbox containers" -> "Sandboxed Containers" (beraldoleal)
- Fix trustee-chart link to validatedpatterns org (beraldoleal)
- Update OCP version refs from 4.17 to 4.19.28+

Enhanced documentation:
- Split prerequisites into Azure and bare metal sections
- Document RuntimeClass differences (kata-remote vs kata-cc vs kata-cc-nvidia-gpu)
- Add PCR update workflow and troubleshooting
- Expand security hardening guidance for production attestation policies
- Add cross-references to multicloud-gitops-sgx and layered-zero-trust patterns
- Update tested environments with v5, bare metal, and GPU configurations
- Add regional availability notes for Azure confidential VMs

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@openshift-ci openshift-ci Bot added size/XXL and removed size/L labels May 7, 2026
Signed-off-by: Chris Butler <chris.butler@redhat.com>
…teness

- Add AMD SEV-SNP support section (equal coverage with Intel TDX)
- Broaden NVIDIA GPU support from H100-only to H100/H200/B100/B200
- Clarify Azure VM families are configurable (not just Standard_DCas_v5)
- Add Intel TDX and AMD SEV vendor documentation links
- Add Technology Preview designation for GPU support
- Note GPU topology supports both Intel TDX and AMD SEV-SNP
- Fix bare metal storage references: HPP not LVMS
- Add 5 new troubleshooting entries:
  * Vault secrets timing out due to MCO reboots
  * ArgoCD apps in per-clusterGroup namespaces
  * CoCo pods starting before initdata annotations ready
  * SGX registration reset needed for TDX cluster rebuilds
  * TEE firmware misconfiguration detection
- Clarify "CoCo pods" terminology throughout troubleshooting
- Add MCO reboot notes to bare metal deployment sections
- Update wordlist: blackwell, epyc, genoa, hpp, milan

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@openshift-ci openshift-ci Bot removed the lgtm label May 7, 2026
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented May 7, 2026

New changes are detected. LGTM label has been removed.

@butler54 butler54 merged commit f370a83 into validatedpatterns:main May 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants