Add a Trusted Execution Environment in form of an image as a read-only system that is also dm-verity baked. The image build provides PCR measuerd UKI image (kernel+initrd+bootloader). The PCR values can be checked against the attestation document and can also serve as AWS KMS key to enforce boot restrictions. The image includes an example workflow in form of an enclave image also build via kiwi using the native eif_build tool from AWS. The enclave runs a little server/client example application which creates the attestion document and sends the enclave PCR measurements as response back to the Trusted Execution instance. The image serves as example into the AWS Nitro TPM Attestation and AWS Nitro Enclaves services to establish a confidential compute workflow. |
||
|---|---|---|
| .. | ||
| arm | ||
| ppc | ||
| s390 | ||
| x86 | ||