Skip to content

metal-prep: CoCo stack in no-TEE dev mode — pinned manifests, Trustee topology decision, sample-attester E2E #9213

Description

@JSONbored

Context

Part of the attested-evaluation epic (#8534). #8536 stands up the CoCo runtime class on SNP metal; everything about that stack except the TEE itself can be built and exercised now using CoCo's no-TEE/sample runtime path on existing hardware or a VM. This issue produces the manifests, pinned versions, and decisions so that #8536 becomes "apply the same manifests on the metal and record real measurements."

Requirements

  1. Committed deploy manifests: k3s RuntimeClass definitions, Kata/CoCo operator install, and (if chosen, see 3) Trustee/KBS — with every version pinned (kata, guest kernel/initrd, CoCo operator, trustee) in a recorded version manifest; version drift fails CI.
  2. Bring the stack up in no-TEE dev mode on an existing host/VM and run the attested-run harness E2E with the sample attester against it.
  3. Decision to record on this issue: verification topology — Trustee/KBS-mediated vs direct attestation-agent → verifier-CLI flow — with the reason.
  4. Document how expected launch measurements will be derived and recorded when real hardware arrives, so SNP day is value-recording, not design work.
  5. Idempotent bring-up/teardown scripts.

Deliverables

  • Manifests + version manifest + scripts + the recorded topology decision + a green dev-mode E2E.

Expected outcome

#8536 on real metal is a config apply plus measurement recording — zero net-new design or code.

Metadata

Metadata

Assignees

Labels

maintainer-onlyOwner-only work — yields no Gittensor points.

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions