Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for trusted launch and SEV-SNP attestation policy management #21918

Closed
1 task done
msanft opened this issue May 24, 2023 · 1 comment · Fixed by #22229
Closed
1 task done

Support for trusted launch and SEV-SNP attestation policy management #21918

msanft opened this issue May 24, 2023 · 1 comment · Fixed by #22229
Labels
enhancement sdk/not-yet-supported Support for this does not exist in the upstream SDK at this time sdk/requires-upgrade This is dependent upon upgrading an SDK service/attestation
Milestone

Comments

@msanft
Copy link
Contributor

msanft commented May 24, 2023

Is there an existing issue for this?

  • I have searched the existing issues

Community Note

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Description

Support for managing attestation policies has been added by #20972 , unfortunately the Azure documentation on the available TEE types is outdated and does not mention the attestation types AzureVM and SEV-SNP

As seen in the Azure portal:
attestation types shown in the azure portal

The Terraform provider should offer support for these two attestation types, respectively.

New or Affected Resource(s)/Data Source(s)

azurerm_attestation_provider

Potential Terraform Configuration

resource "azurerm_attestation_provider" "example" {
  name                = "exampleprovider"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  azure_vm_policy_base64 = "..."
}

resource "azurerm_attestation_provider" "example" {
  name                = "exampleprovider"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  sev_snp_policy_base64 = "..."
}

References

No response

Copy link

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 24, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement sdk/not-yet-supported Support for this does not exist in the upstream SDK at this time sdk/requires-upgrade This is dependent upon upgrading an SDK service/attestation
Projects
None yet
3 participants