Skip to content

fix(kubevirt-instancetypes): restore persistent EFI/TPM state - #3154

Merged
myasnikovdaniil merged 1 commit into
mainfrom
fix/restore-persistent-efi-tpm
Jul 6, 2026
Merged

myasnikovdaniil merged 1 commit into
mainfrom
fix/restore-persistent-efi-tpm

Conversation

@kvaps

@kvaps Andrei Kvapil (kvaps) commented Jun 30, 2026 •

Copy link
Copy Markdown
Member

What this PR does

Reverts #3006, restoring upstream's persistent EFI/TPM firmware state for the windows.11 / windows.2k22 / windows.2k25 preferences (and their .virtio variants).

#3006 dropped persistent EFI/TPM to "unblock live-migration", on the assumption that an RWO Filesystem backend-storage PVC pins the VM to its node. That assumption was outdated: KubeVirt has live-migrated RWO-Filesystem backend storage since v1.4 (kubevirt/kubevirt#12629) — on migration it creates a fresh target state PVC and copies the small state blob. So persistent-EFI/TPM VMs on the default replicated storage live-migrate fine; the regression described in #3005 was a misdiagnosis.

Verified on a KubeVirt v1.8.2 cluster: a persistent-EFI VM with an RWO Filesystem backend PVC reports LiveMigratable=True, and the copy-on-target backend PVC is created when a migration starts. KubeVirt maintainers confirmed the same upstream.

This restores persistent firmware state so in-guest Microsoft UEFI CA / Secure Boot enrollment survives reboots and migrations.

Release note

fix(kubevirt-instancetypes): restore persistent EFI/TPM state for Windows preferences — RWO-Filesystem backend storage already live-migrates (KubeVirt v1.4+), so persistence no longer needs to be stripped

Summary by CodeRabbit

  • Bug Fixes

    • Updated Windows instance type preferences to keep TPM persistence enabled, improving compatibility and reducing storage-related issues.
    • Ensured firmware and TPM persistence settings are preserved during instance type preference generation for more reliable outcomes.
  • Chores

    • Streamlined the preference generation step so instance type templates are produced consistently without removing persistence configuration.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request reverts a previous change that disabled persistent EFI and TPM state for Windows virtual machine preferences. The original change was implemented to avoid potential live-migration issues, but it has been determined that KubeVirt v1.4+ correctly handles live-migration for RWO-Filesystem backend storage by creating and copying the necessary state blobs. Restoring this persistence ensures that in-guest security features like Microsoft UEFI CA and Secure Boot remain functional across VM lifecycle events.

Highlights

  • Restoration of Persistent EFI/TPM: Re-enabled persistent EFI and TPM settings for Windows 11, 2022, and 2025 preferences to ensure Secure Boot and UEFI enrollment survive reboots and migrations.
  • Cleanup of Build Logic: Removed the temporary workaround in the Makefile that was previously stripping persistent EFI/TPM settings.
New Features

🧠 You can now enable Memory (public preview) to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment Gemini (@gemini-code-assist) Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review kind/bug Categorizes issue or PR as related to a bug size/M This PR changes 30-99 lines, ignoring generated files labels Jun 30, 2026
@dosubot dosubot Bot added the area/virtualization Issues or PRs related to virtualization (kubevirt, cdi, vmi, vm-import) label Jun 30, 2026
@coderabbitai

coderabbitai Bot commented Jun 30, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 04690c40-6a7f-4cf6-bb5c-60f957e924fb

📥 Commits

Reviewing files that changed from the base of the PR and between 35e0f00 and 59f035f.

📒 Files selected for processing (2)
  • packages/system/kubevirt-instancetypes/Makefile
  • packages/system/kubevirt-instancetypes/templates/preferences.yaml
💤 Files with no reviewable changes (1)
  • packages/system/kubevirt-instancetypes/Makefile
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/system/kubevirt-instancetypes/templates/preferences.yaml

📝 Walkthrough

Walkthrough

Removes a Makefile workaround that stripped persistent TPM and EFI fields during preference generation. Six Windows preference resources now explicitly set spec.devices.preferredTPM.persistent: true.

Changes

Windows preferredTPM persistence enabled

Layer / File(s) Summary
Remove yq strip workaround from Makefile
packages/system/kubevirt-instancetypes/Makefile
Deletes the temporary yq step that removed .spec.firmware.preferredEfi.persistent and .spec.devices.preferredTPM.persistent from preferences.yaml during the update target.
Set preferredTPM.persistent: true in Windows preferences
packages/system/kubevirt-instancetypes/templates/preferences.yaml
Updates windows.11, windows.11.virtio, windows.2k22, windows.2k22.virtio, windows.2k25, and windows.2k25.virtio to use preferredTPM: { persistent: true } instead of preferredTPM: {}.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related issues

Possibly related PRs

  • cozystack/cozystack#3006: Directly related — it modified the same Windows preference persistence behavior in the opposite direction.

Suggested reviewers: myasnikovdaniil

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: restoring persistent EFI/TPM state for kubevirt instancetypes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/restore-persistent-efi-tpm

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request removes a temporary workaround in the kubevirt-instancetypes Makefile that previously stripped persistent EFI and TPM state from the KubeVirt preferences. Consequently, the preferences.yaml template has been updated to restore persistent: true for both preferredTPM and preferredEfi across various configurations. I have no feedback to provide as the changes are straightforward and correctly revert the temporary workaround.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@myasnikovdaniil

Copy link
Copy Markdown
Contributor

Andrei Kvapil (@kvaps) rebase please

Reverts #3006. Dropping persistent EFI/TPM was motivated by a live-migration
concern that rested on an outdated assumption — that an RWO Filesystem
backend-storage PVC pins the VM to its node. KubeVirt has migrated
RWO-Filesystem backend storage since v1.4 (kubevirt/kubevirt#12629): on
migration it creates a fresh target state PVC and copies the small state blob,
so persistent-EFI/TPM VMs on the default replicated storage live-migrate fine
(verified: the VM reports LiveMigratable=True and the copy-on-target PVC is
created on migration). Restore upstream's persistent firmware state for the
windows.* preferences.

Assisted-By: Claude <[email protected]>
Signed-off-by: Andrei Kvapil <[email protected]>
@myasnikovdaniil
myasnikovdaniil force-pushed the fix/restore-persistent-efi-tpm branch from 35e0f00 to 59f035f Compare July 6, 2026 04:51

@myasnikovdaniil myasnikovdaniil left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — correct revert. On KubeVirt v1.8.4 (what we ship) RWO-Filesystem backend storage live-migrates by copy (kubevirt/kubevirt#12629, v1.4+) and VMPersistentState is GA, so persistent EFI/TPM no longer pins the VM — #3005's premise doesn't hold. Worth closing #3005.

@myasnikovdaniil
myasnikovdaniil enabled auto-merge July 6, 2026 05:16
@myasnikovdaniil
myasnikovdaniil merged commit e28681a into main Jul 6, 2026
17 checks passed
@myasnikovdaniil
myasnikovdaniil deleted the fix/restore-persistent-efi-tpm branch July 6, 2026 06:07
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

Successfully created backport PR for release-1.5:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/uncategorized PR auto-labeler could not map title scope to a known area/*; please review area/virtualization Issues or PRs related to virtualization (kubevirt, cdi, vmi, vm-import) kind/backport Categorizes issue or PR as requiring a backport to the current release line kind/bug Categorizes issue or PR as related to a bug size/M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants