Attested build of confidential-containers/trustee
32
Cryptographically attested builds of confidential-containers/trustee, produced
inside a Confidential VM by Kettle.
Every build carries hardware-signed SLSA provenance, so anyone can verify exactly
which source, dependencies, and toolchain produced the binaries.
Image tags are the git commit SHA that was built.
Builds are OCI artifacts, pulled with oras:
oras pull docker.io/confidentialai/confidential-containers-trustee:fd3ab9c8d683110b18ae54b132980376f84ba63a
This drops provenance.json, evidence.json, and the built binaries into the
current directory.
Install Kettle, then verify the pulled artifact:
kettle verify .
Kettle reads evidence.json, verifies the hardware signature against the vendor's
public keys, then validates the signed provenance.json and confirms the binary
checksums.
The check above proves the build's attestation. To verify the full launch chain (hardware launch measurement -> the exact IGVM that booted the CVM -> the dm-verity root hash committed in that IGVM -> the actual VM disk image), pull the exact, digest-pinned confidential-VM image this build ran on and re-run verification against it:
oras pull ghcr.io/confidential-dot-ai/kettle-build@sha256:4f001fee77146b863324bf66df547897da646e2c265f093750fd3caf031cb8f8
kettle verify . --igvm guest-smp10.igvm --image disk.raw
Content type
Unrecognized
Digest
sha256:2408572f3…
Size
64 MB
Last updated
3 months ago
docker pull confidentialai/confidential-containers-trustee:fd3ab9c8d683110b18ae54b132980376f84ba63a