Skip to content

feat: deploy in azure - #203

Open
zbitname wants to merge 37 commits into
mainfrom
feature/azure-deploy-with-sp-vm
Open

zbitname wants to merge 37 commits into
mainfrom
feature/azure-deploy-with-sp-vm

Conversation

@zbitname

Copy link
Copy Markdown
Collaborator

No description provided.

@coderabbitai

coderabbitai Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: fb117389-3552-41c0-8f52-b1e13aae8ce5

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zbitname
zbitname force-pushed the feature/azure-deploy-with-sp-vm branch from d05b97a to ca64210 Compare September 1, 2026 09:11
zbitname and others added 17 commits September 1, 2026 15:24
olddefconfig after forcing CONFIG_HYPERV_STORAGE=y can set it back to =m when SCSI_FC_ATTRS is a module; initramfs then has no disks. Verify IKCONFIG on bzImage and rebuild initramfs without cache.

Co-authored-by: Cursor <cursoragent@cursor.com>
Linux 6.12 rejects CONFIG_HYPERV_STORAGE=y when SCSI_FC_ATTRS is a module, so Azure initramfs never sees VMBus disks. Disable unused FC attrs, fail the image build if System.map lacks hv_acpi_init/hv_storvsc, and add busybox sleep for the root-device wait loop.

Co-authored-by: Cursor <cursoragent@cursor.com>
build-sp-vm.yml only assembled the VM from the pinned sp-vm-low-level-v1
release, so Azure kept booting a virtio kernel. Build Dockerfile.low-level
first and inject it via --build-context low_level_assets.

Co-authored-by: Cursor <cursoragent@cursor.com>
-y kept CONFIG_NETFILTER_XT_*=y over later =m fragments and allnoconfig then dropped those symbols (and CONFIG_IP_PNP_DHCP). Hyper-V builtin is still forced after merge.

Co-authored-by: Cursor <cursoragent@cursor.com>
Whitelist the known drop, then re-enable IP_PNP/DHCP after merge so Azure ip=dhcp still works. Stop requesting SCSI_FC_ATTRS n from the fragment during merge.

Co-authored-by: Cursor <cursoragent@cursor.com>
…y logging

Simplified the get_device function to focus solely on partition labels, enhancing clarity. Removed redundant logging related to Hyper-V devices and configuration checks in the init script, improving overall efficiency and readability.
Eliminated the unnecessary net.ifnames=0 parameter from the kernel boot options in both the 'SP Linux Prod' and 'SP Linux Debug' menu entries, streamlining the configuration for improved clarity and consistency.
Keep console/earlyprintk only on Debug so GCP and bare metal Prod boots stay unchanged.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop balloon, vsocks, PCI, IOMMU, and MANA extras that are not required to boot Azure Gen2.

Co-authored-by: Cursor <cursoragent@cursor.com>
@zbitname zbitname changed the title feat: update .gitignore and add Hyper-V configuration for kernel feat: deploy in azure Sep 7, 2026
zbitname and others added 9 commits September 8, 2026 15:47
… support

- Added Microsoft Azure Attestation (MAA) as a trust source for hardware evidence verification in the architecture document.
- Enhanced first VM bootstrap documentation to include detection of Azure TDX (`tdx-azure`) and its specific requirements.
- Updated node join and PKI documents to reflect the inclusion of `tdx-azure` as an allowed attested device type.
- Revised VM measurements chapter to detail the `mrEnclave` calculation for Azure TDX, including conditions for evidence rejection.
- Updated README and reference measurements to mention Azure TDX support.
- Updated Dockerfile and package dependencies for Azure TDX quote CLI integration.
…guest attestation

- Updated the VM measurements documentation to specify the absence of the CCEL table in Azure TDX guests and clarified the handling of PCR values, particularly PCR[6].
- Introduced a new script for installing the Azure guest attestation tool, including versioning and SHA256 verification for security.
DCeds_v6 exposes the OS disk as Hyper-V NVMe PCI; hv_storvsc plus netvsc was not enough for SSH.

Co-authored-by: Cursor <cursoragent@cursor.com>
CONFIG_MICROSOFT_MANA is not visible during fragment merge and dropped #432.

Co-authored-by: Cursor <cursoragent@cursor.com>
# Conflicts:
#	src/rootfs/files/configs/npm/pki-components/package-lock.json
#	src/rootfs/files/configs/npm/pki-components/package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants