Skip to main content

Secure Containers — supported production profile

Name: fluxvm-sc-supported (informal).
Status: GA RuntimeClass with documented boundaries — not full Kata Containers compatibility.

This is the profile buyers can run in production without soft language. Outside this matrix, stay on Kata/CoCo or treat the workload as lab-only.

Supported matrix​

ConstraintSupportedNotes
VMMQEMU (primary); Cloud Hypervisor allowedSet FLUXVM_CONTAINER_BACKEND=qemu or cloud-hypervisor
FirecrackerBlock-share path onlyNo live virtio-fs; Pod shares packed to ext4 at launch; needs FLUXVM_CONTAINER_KERNEL
CNI primaryCilium, Calico, or FlannelAuto-detect via FLUXVM_CONTAINER_CNI_PROVIDER; datapath auto (direct with bridge fallback)
MultusSecondary NICs opt-inHybrid bridge default; FLUXVM_CONTAINER_CNI_MULTUS_DATAPATH=direct|auto when ready
hostPathAllowlist / broker onlyFLUXVM_HOSTPATH_ALLOW and/or FLUXVM_HOSTPATH_BROKER=1 (QEMU/CH hotplug)
Guest imageguestkit-baked Fedora or Ubuntu SC guestPrefer signed catalog entries; token inject via guestkit (no virt-customize in the FluxVM path)
PolicyIn-cluster NetworkPolicy → SentinelHost TC + optional guest cgroup_skb mirror; opt-in remote seccomp NOTIFY RPC (mode=remote)
Isolation extrasOpt-in CLONE_NEWUSER, SELinux linux.mountLabel, seccomp NOTIFYLive evidence under docs/benchmarks/evidence/sc-live-*.txt
TEE / confidentialOut of profileSC is isolation without TEE. SNP/TDX + attestation stays Ragnarok + Kata/KubeVirt

Parity vs Kata (decision table)​

CapabilityFluxVM SCStay on Kata / CoCo when…
Pod → own guest kernelYes (RuntimeClass fluxvm)You need Kata’s exact packaging / ecosystem tooling
OCI RuntimeClass drop-inYes (runtimeClassName: fluxvm)You already standardized on kata RuntimeClasses cluster-wide
Live virtio-fs write-throughQEMU/CH yes; Firecracker noYou require FC + live virtio-fs
Unrestricted hostPathNo (allowlist / fail-closed)You require arbitrary host binds
Remote seccomp policy RPCOpt-in mode=remoteGuest→host AF_VSOCK; default deny; HTTP via FLUXVM_SECCOMP_POLICY_RPC_URL
Host + guest eBPF NetworkPolicy (Sentinel)Yes — sentinel-wedge.mdYou only need Kata’s static policy files
SEV-SNP / TDX attestationNoYou need hardware TEE + attest-gated secrets
CDI / virtctl / KubeVirt APINoYou need that control plane

Non-goals (keep)​

  • Feature-for-feature Kata / CDI / virtctl
  • Claiming remote seccomp RPC as a Kata-compatible policy file drop-in
  • Claiming in-tree virtio-fs is as deep as Cloud Hypervisor under load (prefer CH for production shared-FS)
  • Claiming SC as confidential / TEE

Evidence​

Live lab pack (dated): benchmarks/evidence/sc-hotcake-bundle-20260926.txt
Flip runbook: secure-containers-flip-runtimeclass.md
Rollup: secure-containers.md