Skip to content

Confidential Container Tools and Components

FOSSA Status OpenSSF Scorecard

This repository includes tools and components for confidential container images.

Components

Attestation Agent An agent for facilitating attestation protocols. Can be built as a library to run in a process-based enclave or built as a process that runs inside a confidential vm.

image-rs Rust implementation of the container image management library.

ocicrypt-rs Rust implementation of the OCI image encryption library.

api-server-rest CoCo RESTful API server.

confidential-data-hub Confidential Data Hub.

coco-keyprovider CoCo Keyprovider. Used to encrypt the container images.

Tools

secret-cli Utility for sealing and unsealing sealed secrets

CDH Client A tool for exercising CDH endpoints

CDH (One Shot) One Shot version of CDH

CoCo Keyprovider Keyprovider endpoint for encrypting images

Build

A Makefile is provided to quickly build Attestation Agent/Api Server Rest/Confidential Data Hub for a given platform.

make build TEE_PLATFORM=$(TEE_PLATFORM)
make install DESTDIR=/usr/local/bin

The TEE_PLATFORM parameter can be

  • none: for tests with non-confidential guests
  • all: for all following platforms
  • fs: for platforms with encrypted root filesystems (i.e. s390x)
  • tdx: for Intel TDX
  • az-tdx-vtpm: for Intel TDX with Azure vTPM
  • snp/amd: for AMD SEV-SNP
  • az-snp-vtpm: for AMD SEV-SNP with Azure vTPM
  • se: for IBM Secure Execution (SE)

By default, the kbs feature (cc_kbc / CoCo KBS) is enabled in Confidential Data Hub. offline_fs_kbc is always built. To build without cc_kbc, set ENABLE_KBS=false:

make build TEE_PLATFORM=$(TEE_PLATFORM) ENABLE_KBS=false

Optional build parameters

The ttRPC and gRPC protos can be updated via run

make build-protos

License

FOSSA Status

About

Confidential Containers Guest Tools and Components

Resources

Code of conduct

Contributing

Security policy

Stars

132 stars

Watchers

22 watching

Forks

Releases

Packages

Used by

Contributors

Languages