Skip to content

Cluster Policy

The QHxClusterPolicy is a singleton, non-namespaced Kubernetes resource used to define policy for an entire QHx cluster. At most one such policy can be created.

Resource Type Names & Abbreviations
QHxClusterPolicy, qhxcp
API Version
qhx.dev/v1
Namespaced
No

QHx can operate without a QHxClusterPolicy being created. A QHxClusterPolicy is only needed if it is desired to define an MLS mapping.

Default: mldsa65

Permitted values: mldsa44, mldsa65, mldsa87, dilithium3, ec-p256†, ec-p384†, rsa-2048†, rsa-4096†

† Non-quantum-safe conventional algorithms supported for compatibility.

If this setting is set to inherit, the value is inherited from QHxClusterPolicy (if created), or from the system-level default.

mldsa44, mldsa65 and mldsa87 correspond to quantum-safe ML-DSA (FIPS 204). ec-p256 and ec-p384 correspond to NIST ECDSA and represent non-quantum-safe conventional signature algorithms. rsa-2048 and rsa-2048 correspond to the RSA non-quantum-safe conventional signature algorithm.

Default: false

Example:

spec:
sealed: false

If set to true, the QHxClusterPolicy becomes permanently immutable without Kubernetes control plane-level intervention or uninstalling QHx. This can be used to provide permanent assurance of a specific MLS policy.

This object defines TPM/PCR-based attestation settings used as the cluster-default attestation policy. TPM-based attestation is disabled by default.

Fields:

  • enable (boolean): Enable TPM-based node attestation. Defaults to false.
  • trustedEKs (array of strings): Array of PEM-encoded trusted TPM EK root certificates. These are a TPM vendor’s TPM endorsement key hierarchy root CA certificates.
  • pcrs: One or more allowed PCR values (as an array of hex strings) for each given PCR.

Example:

spec:
tpm:
enable: true
trustedEKs:
- |
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
pcrs:
"0":
- cfdff6cf749bdef553e754c04001e92efff6cc9fa05a639e5a14ce28c9738e2b
- 9db76a831f70243c8d606018163b25b35a102685e84f7383ca919a7995dadb73

Default: {}

Example:

spec:
groupToLevelMapping:
- "level:c": "us:c"
- "level:s": "us:s"
- "level:ts": "us:ts"

This mapping maps Kubernetes groups to QHx MLS level descriptors. See the QHx labelling specification for detalis on QHx MLS level descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

Default: {}

Example:

spec:
groupToReleasabilityMapping:
- "rel:fvey": "us,uk,ca,au,nz"

This mapping maps Kubernetes groups to QHx MLS releasability descriptors. See the QHx labelling specification for detalis on QHx MLS releasability descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

Default: {}

Example:

spec:
groupToCompartmentMapping:
- "compartment:quantum": "us:quantum"
- "compartment:marble": "us:marble"

This mapping maps Kubernetes groups to QHx MLS compartment descriptors. See the QHx labelling specification for detalis on QHx MLS compartment descriptors. Groups may be chosen arbitrarily according to the Kubernetes environment.

An annotated example QHxClusterPolicy is as follows:

---
apiVersion: qhx.dev/v1
kind: QHxClusterPolicy
metadata:
name: qhx-cluster-policy
spec:
## This defaults to false. If set to true, the QHxClusterPolicy becomes permanently
## immutable without Kubernetes control plane-level intervention or uninstalling QHx.
## This can be used to provide permanent assurance of a specific MLS policy.
sealed: false
## This mapping maps Kubernetes groups to QHx MLS level descriptors.
## See the QHx labelling specification for details on QHx MLS level descriptors.
## Groups may be chosen arbitrarily according to the Kubernetes environment.
groupToLevelMapping:
- "level:c": "us:c"
- "level:s": "us:s"
- "level:ts": "us:ts"
## This mapping maps Kubernetes groups to QHx MLS releasability descriptors.
## See the QHx labelling specification for details on QHx MLS releasability descriptors.
groupToReleasabilityMapping:
- "rel:fvey": "us,uk,ca,au,nz"
## This mapping maps Kubernetes groups to QHx MLS compartment descriptors.
## See the QHx labelling specification for details on QHx MLS compartment descriptors.
groupToCompartmentMapping:
- "compartment:quantum": "us:quantum"
- "compartment:marble": "us:marble"
## Use the ML-DSA-65 post-quantum-safe NIST signature algorithm by default for namespaces
## without a custom QHxPolicy.
signatureAlgorithm: mldsa65
## TPM node attestation defaults to disabled unless explicitly enabled.
tpm:
enable: false