demo: IAA/DSA: deploy with SYS_RAWIO capabilities

stable kernel update added a patch that requires processes to
carry SYS_RAWIO in order to submit IAA/DSA commands.

This isn't enabled for containers by default  so explicitly
request adding it for test deployments.

Signed-off-by: Mikko Ylinen <mikko.ylinen@intel.com>
This commit is contained in:
Mikko Ylinen 2024-08-05 14:54:01 +03:00
parent 2423ce4e67
commit 24fe81ee9f
2 changed files with 8 additions and 2 deletions

View File

@ -17,6 +17,9 @@ spec:
resources: resources:
limits: limits:
dsa.intel.com/wq-user-dedicated: 1 dsa.intel.com/wq-user-dedicated: 1
# In kernels 5.13-5.17, ENQCMD is disabled (is to be reinstated in 5.18)
# dsa.intel.com/wq-user-shared: 1 # dsa.intel.com/wq-user-shared: 1
securityContext:
capabilities:
add:
["SYS_RAWIO"]
restartPolicy: Never restartPolicy: Never

View File

@ -17,6 +17,9 @@ spec:
resources: resources:
limits: limits:
iaa.intel.com/wq-user-dedicated: 1 iaa.intel.com/wq-user-dedicated: 1
# In kernels 5.13-5.17, ENQCMD is disabled (is to be reinstated in 5.18)
# iaa.intel.com/wq-user-shared: 1 # iaa.intel.com/wq-user-shared: 1
securityContext:
capabilities:
add:
["SYS_RAWIO"]
restartPolicy: Never restartPolicy: Never