Skip to content

TEE Host Validated Build — Kubespray deployment path via Akash provider playbooks (AMD SEV-SNP + NVIDIA Blackwell) #517

@linear

Description

@linear

Validate that the AMD SEV-SNP + NVIDIA Blackwell confidential compute stack runs end-to-end on a Kubernetes cluster deployed via Kubespray, using the official Akash provider-playbooks install script (akash-network/provider-playbooks). This is the production-relevant deployment path for Akash GPU providers; the K3s path is tracked separately as an alternative.

Scope: stock Ubuntu 26.04 LTS on the same hardware; Kubespray v2.31.0 → Kubernetes v1.35.4, containerd 2.2.3, Calico 3.31.5; the Akash install script driven interactively with only the Kubespray component selected (no GPU drivers, no Akash provider service, no other optional components); kata-deploy v3.29.0; NVIDIA GPU Operator v26.3.1 in sandboxWorkloads.mode=kata. Validation criterion: same as K3s path — both runtime classes pass with SEV-SNP active at VMPL0 inside the guest, CUDA workload completes on the confidential GPU. Aligns with the broader Akash TEE workstream.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions