Matias Ezequiel Vara Larsen
unread,Mar 4, 2026, 1:34:55 PMMar 4Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Aseef Imran, Vladik Romanovsky, kubevirt-dev, Stefano Garzarella, Javier Cano Cano, Itamar Holder, German Maglione, Roman Mohry, Mikko Ylinen, Zhenchao Liu
Hello Aseef,
On Tue, Mar 3, 2026 at 1:33 PM Aseef Imran <
aim...@redhat.com> wrote:
>
> Hi everyone,
>
> The next Confidential Computing WG meeting is scheduled for Tuesday, March 10⋅11:00am – 12:00pm EST on the KubeVirt calendar, however it is currently marked as "tentatively cancelled".
>
> Now that in
https://github.com/kubevirt/kubevirt/pull/15958 the PR adding attestation for TDX is merged, I was hoping to discuss and converge on some remaining questions as we head into the beta phase for TDX. I don't know if the meeting is marked as cancelled because we do not have any discussion topics, but if so, there are a few matters I was hoping to discuss. Discussing them over the mailing list is also acceptable to me.
>
Thanks for all the work you did to get that merged!
> These open questions are formalized in
https://github.com/kubevirt/enhancements/pull/220/changes. Just for your convenience, I am copying and pasting these open questions from this PRs below:
> - Decide whether to keep the `confidentialCompute.tdx.attestion.qgsSocketPath`
> configuration option to custom QGS path locations or to remove it in favor of
> a default location (i.e. `/var/run/tdx-qgs/qgs.socket`).
> - Decide whether to enforce the existance of QGS on the KubeVirt side (i.e use
> of the `confidentialCompute.tdx.attestation.enforced` field) and if so whether
> it makes sense to extend these enforcements to support per-VMI enforcements (as
> opposed to only cluster-wide).
I have a feeling that we will figure out these open questions after
people start using it and complain. For example, if most people are
using the default location, we can remove it as a parameter. I think
this is also true for the enforced field.
Matias.