Skip to content
This repository has been archived by the owner on Oct 24, 2023. It is now read-only.

fix: Updated sgx driver download urls. Fixes issue 2743 #2807

Merged
merged 1 commit into from
Mar 4, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions parts/k8s/cloud-init/artifacts/cse_install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -125,10 +125,10 @@ installSGXDrivers() {
VERSION=$(grep DISTRIB_RELEASE /etc/*-release| cut -f 2 -d "=")
case $VERSION in
"18.04")
SGX_DRIVER_URL="https://download.01.org/intel-sgx/dcap-1.2/linux/dcap_installers/ubuntuServer18.04/sgx_linux_x64_driver_1.12_c110012.bin"
SGX_DRIVER_URL="https://download.01.org/intel-sgx/latest/dcap-latest/linux/distro/ubuntuServer18.04/sgx_linux_x64_driver_1.21.bin"
Copy link
Member

@mboersma mboersma Feb 28, 2020

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this URL going to break when there's a new sgx_linux driver release? I'm guessing from the contents of https://download.01.org/intel-sgx/latest/dcap-latest/linux/distro/ubuntuServer18.04/ that the 1.22 release (for example) would replace this one, which would break our CSE.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@mboersma you are assuming based on the presence of a single versioned artifact in that directory that only one at a time ever lives there?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, although I could be wrong.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@yakman2020 can you confirm whether or not this URL will be resilient when the next version drops?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Given that SGX drivers installation is currently broken we'll merge this as-is, with the understanding that it may break again in the future

;;
"16.04")
SGX_DRIVER_URL="https://download.01.org/intel-sgx/dcap-1.2/linux/dcap_installers/ubuntuServer16.04/sgx_linux_x64_driver_1.12_c110012.bin"
SGX_DRIVER_URL="https://download.01.org/intel-sgx/latest/dcap-latest/linux/distro/ubuntuServer16.04/sgx_linux_x64_driver_1.21.bin"
;;
"*")
echo "$VERSION is not supported"
Expand Down
4 changes: 2 additions & 2 deletions pkg/engine/templates_generated.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

51 changes: 51 additions & 0 deletions test/e2e/test_cluster_configs/sgx.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
{
"env": {
"REGION_OPTIONS": "westeurope",
"GINKGO_SKIP": "should have healthy time synchronization|should create a pv by deploying a pod that consumes a pvc"
},
"options": {
"allowedOrchestratorVersions": [
"1.13",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We're not testing Kubernetes 1.13 as of #2749.

"1.14",
"1.15",
"1.16"
]
},
"apiModel": {
"apiVersion": "vlabs",
"properties": {
"orchestratorProfile": {
"orchestratorType": "Kubernetes"
},
"masterProfile": {
"count": 1,
"vmSize": "Standard_D2s_v3",
"dnsPrefix": ""
},
"agentPoolProfiles": [
{
"name": "agentpool",
"count": 1,
"availabilityProfile": "VirtualMachineScaleSets",
"distro": "aks-ubuntu-18.04",
"vmSize": "Standard_DC2s",
"storageProfile": "ManagedDisks"
}
],
"linuxProfile": {
"adminUsername": "azureuser",
"ssh": {
"publicKeys": [
{
"keyData": ""
}
]
}
},
"servicePrincipalProfile": {
"clientId": "",
"secret": ""
}
}
}
}