Exception Request for VEP #287 - TLS Group Preferences

12 views
Skip to first unread message

Lee Yarwood

unread,
Sep 2, 2026, 10:42:03 AMSep 2
to kubevirt-dev
Hi all,

I'd like to request a VEP freeze exception for VEP #287, TLS Group
Preferences (owning SIG: compute; assignee @Barakmor1).

- Tracking issue: https://github.com/kubevirt/enhancements/issues/287
- VEP PR (retarget + API finalisation):
https://github.com/kubevirt/enhancements/pull/442
- Target: Beta in v1.10.0, behind the TLSGroupPreferences feature gate

1. Justification
PR #442 retargets the VEP to v1.10 and finalises the API design,
adding an open Groups []string field to the existing GA
TLSConfiguration to allow configuring TLS supported groups (elliptic
curves), enabling Post-Quantum Cryptography readiness (e.g.
X25519MLKEM768). This is the most actively debated of our outstanding
VEPs: the open-string-set-vs-enum modelling, the CEL declarative
validation rule, and the skip-Alpha/direct-to-Beta decision have all
been under review (most recently with @nunnatsa). The discussion is
converging and the remaining points are narrow rather than
fundamental.

2. Additional time requested
One week from the freeze date to settle the open review threads and
merge. If consensus on the direct-to-Beta entry needs longer, the
fallback is to merge with an Alpha target for v1.10.0 and defer the
Beta decision, which keeps the feature moving without holding the
freeze open indefinitely.

3. Impact if not granted
Deferring to the next cycle delays PQC readiness across KubeVirt's TLS
endpoints by a full release and blocks the alpha implementation PR
(kubevirt/kubevirt#17553), which already implements the open []string
design. Given the field is an additive, opt-in extension of an
already-GA API with zero blast radius when unset, the cost of slipping
is disproportionate to the small amount of review time remaining.

Thanks,
Lee

Itamar Holder

unread,
Sep 9, 2026, 7:46:34 AMSep 9
to Lee Yarwood, kubevirt-dev
Hey Lee,

This VEP PR was submitted extremely late - one week before the freeze. This is way too late for a proper review. In addition, IIUC this VEP was not implemented or moved forward during v1.9, the VEP's original target version, and now it targets Beta for v1.10.

Due to these reasons, we must decline this exception request.

That being said, re-targeting the alpha version for v1.10 makes sense since the VEP PR was already merged for v1.9. If you decide to re-target this to alpha, consider this exception granted and please try to merge the PR as soon as possible.

Good luck!

--
You received this message because you are subscribed to the Google Groups "kubevirt-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to kubevirt-dev...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/kubevirt-dev/CAPkJ9DtcxFVqcRnr1SzVDSUgXHCFeydJjSnot7oyy_6dGAsuEQ%40mail.gmail.com.

Or Mergi

unread,
Sep 9, 2026, 7:55:00 AMSep 9
to Itamar Holder, Lee Yarwood, kubevirt-dev
FWIW:
This change comes down to adding yet another TLS setting to KubeVirt API resource, similar to previous work done in this area (adding Kubevirt.Spec.TLSConfiguration[MinTLSVersion, Ciphers), it should be straight forward.
I can assist with reviews.




--
Or Mergi
Reply all
Reply to author
Forward
0 new messages