Attested build of confidential-containers/guest-components
36
Cryptographically attested builds of confidential-containers/guest-components, produced
inside a Confidential VM by Kettle.
Every build carries hardware-signed SLSA provenance, so anyone can verify exactly
which source, dependencies, and toolchain produced the binaries.
Image tags are the git commit SHA that was built.
Builds are OCI artifacts, pulled with oras:
oras pull docker.io/confidentialai/confidential-containers-guest-components:740b92fffcb1bd164cdd238efd2913d1a296ec4b
This drops provenance.json, evidence.json, and the built binaries into the
current directory.
Install Kettle, then verify the pulled artifact:
kettle verify .
Kettle reads evidence.json, verifies the hardware signature against the vendor's
public keys, then validates the signed provenance.json and confirms the binary
checksums.
The check above proves the build's attestation. To verify the full launch chain (hardware launch measurement -> the exact IGVM that booted the CVM -> the dm-verity root hash committed in that IGVM -> the actual VM disk image), pull the exact, digest-pinned confidential-VM image this build ran on and re-run verification against it:
oras pull docker.io/confidentialai/kettle-server@sha256:287fe375cd0a620f7cc45c8940f1228e5319b6e2b5d5568b0b66a4474db8c6f6
kettle verify . --igvm guest-smp10.igvm --image disk.raw
Content type
Unrecognized
Digest
sha256:a70d74eb6…
Size
67.6 MB
Last updated
3 months ago
docker pull confidentialai/confidential-containers-guest-components:740b92fffcb1bd164cdd238efd2913d1a296ec4b