7.9. 创建信任配置映射
您必须创建配置映射来配置 Trustee 服务器。
注意
以下配置示例关闭了安全功能,以启用技术预览功能演示。它不适用于生产环境。
先决条件
- 您已为 Trustee 创建了路由。
流程
创建
kbs-config-cm.yaml
清单文件:apiVersion: v1 kind: ConfigMap metadata: name: kbs-config-cm namespace: trustee-operator-system data: kbs-config.json: | { "insecure_http" : true, "sockets": ["0.0.0.0:8080"], "auth_public_key": "/etc/auth-secret/publicKey", "attestation_token_config": { "attestation_token_type": "CoCo" }, "repository_config": { "type": "LocalFs", "dir_path": "/opt/confidential-containers/kbs/repository" }, "as_config": { "work_dir": "/opt/confidential-containers/attestation-service", "policy_engine": "opa", "attestation_token_broker": "Simple", "attestation_token_config": { "duration_min": 5 }, "rvps_config": { "store_type": "LocalJson", "store_config": { "file_path": "/opt/confidential-containers/rvps/reference-values/reference-values.json" } } }, "policy_engine_config": { "policy_path": "/opt/confidential-containers/opa/policy.rego" } }
运行以下命令来创建配置映射:
$ oc apply -f kbs-config-cm.yaml