kiwi-el8/build-tests
Marcus Schäfer 9387737714
Add confidential compute image for AWS
Add a Trusted Execution Environment in form of an image as
a read-only system that is also dm-verity baked. The image
build provides PCR measuerd UKI image (kernel+initrd+bootloader).
The PCR values can be checked against the attestation document
and can also serve as AWS KMS key to enforce boot restrictions.
The image includes an example workflow in form of an enclave
image also build via kiwi using the native eif_build tool from
AWS. The enclave runs a little server/client example application
which creates the attestion document and sends the enclave
PCR measurements as response back to the Trusted Execution
instance. The image serves as example into the AWS Nitro TPM
Attestation and AWS Nitro Enclaves services to establish a
confidential compute workflow.
2026-03-02 17:14:28 +01:00
..
arm Move fedora arm build test to dnf5 2026-01-26 12:02:59 +01:00
ppc Cleanup integration tests config.sh script code 2025-07-14 18:24:23 +02:00
s390 Add registration utility 2025-11-26 10:41:06 +01:00
x86 Add confidential compute image for AWS 2026-03-02 17:14:28 +01:00