-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
rfc: genpolicy on diverse platforms #761
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for writing this down!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks a lot for writing this!
|
||
### Bundle both Microsoft's and Kata's tool | ||
|
||
While this approach seems easiest on the surface, it's going to explode the size of the CLI binary, which is already significant. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see the second point, but I think there could be ways around a large CLI (e.g. by sourcing static builds of these tools at runtime, only for the required platform)
Just a note though, not advocating against your proposal
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There's also other drawbacks, like increased TCB etc., but given the other arguments against it I don't think I need to add workarounds to the proposal text.
Co-authored-by: Moritz Sanft <[email protected]> Co-authored-by: Paul Meyer <[email protected]> Co-authored-by: Moritz Eckert <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
No description provided.