This repository includes tools and components for confidential container images.
Attestation Agent An agent for facilitating attestation protocols. Can be built as a library to run in a process-based enclave or built as a process that runs inside a confidential vm.
image-rs Rust implementation of the container image management library.
ocicrypt-rs Rust implementation of the OCI image encryption library.
api-server-rest CoCo RESTful API server.
confidential-data-hub Confidential Data Hub.
coco-keyprovider CoCo Keyprovider. Used to encrypt the container images.
secret-cli Utility for sealing and unsealing sealed secrets
CDH Client A tool for exercising CDH endpoints
CDH (One Shot) One Shot version of CDH
CoCo Keyprovider Keyprovider endpoint for encrypting images
A Makefile is provided to quickly build Attestation Agent/Api Server Rest/Confidential Data Hub for a given platform.
make build TEE_PLATFORM=$(TEE_PLATFORM)
make install DESTDIR=/usr/local/binThe TEE_PLATFORM parameter can be
none: for tests with non-confidential guestsall: for all following platformsfs: for platforms with encrypted root filesystems (i.e. s390x)tdx: for Intel TDXaz-tdx-vtpm: for Intel TDX with Azure vTPMsnp/amd: for AMD SEV-SNPaz-snp-vtpm: for AMD SEV-SNP with Azure vTPMse: for IBM Secure Execution (SE)
By default, the kbs feature (cc_kbc / CoCo KBS) is enabled in Confidential
Data Hub. offline_fs_kbc is always built. To build without cc_kbc, set
ENABLE_KBS=false:
make build TEE_PLATFORM=$(TEE_PLATFORM) ENABLE_KBS=falseThe ttRPC and gRPC protos can be updated via run
make build-protos