Open db376 opened 1 month ago
There are two factors at work here:
I've been considering ways to address (2) recently since we have two newly added external kmods - the Neuron driver and the NVIDIA open source driver - that really ought to be signed and trusted.
When attempting to load the NVIDIA kernel module on a Bottlerocket AMI using kernel lockdown =
integrity
, errors like the following are produced:This was tested on the following versions in us-east-1: 1.30 (
ami-0c2f741e432159b2c
), 1.29 (ami-06033e6f46c64c7db
), and 1.20 (ami-046b028e6b00a3938
).Sef-signing also does not work as a workaround - rather, we receive validation rejected.