This is essentially kata-containers/kata-containers#9706, but adopted to Microsoft's fork.
Since the patch touches rules.rego, we can't take the one from the URL anymore, so I changed the rules to small derivations that extract the patched rules.rego and genpolicy-settings.json files, respectively.
This is essentially kata-containers/kata-containers#9706, but adopted to Microsoft's fork.
Since the patch touches
rules.rego
, we can't take the one from the URL anymore, so I changed the rules to small derivations that extract the patchedrules.rego
andgenpolicy-settings.json
files, respectively.