Context
Part of the attested-evaluation epic (#8534). #8536 stands up the CoCo runtime class on SNP metal; everything about that stack except the TEE itself can be built and exercised now using CoCo's no-TEE/sample runtime path on existing hardware or a VM. This issue produces the manifests, pinned versions, and decisions so that #8536 becomes "apply the same manifests on the metal and record real measurements."
Requirements
- Committed deploy manifests: k3s RuntimeClass definitions, Kata/CoCo operator install, and (if chosen, see 3) Trustee/KBS — with every version pinned (kata, guest kernel/initrd, CoCo operator, trustee) in a recorded version manifest; version drift fails CI.
- Bring the stack up in no-TEE dev mode on an existing host/VM and run the attested-run harness E2E with the sample attester against it.
- Decision to record on this issue: verification topology — Trustee/KBS-mediated vs direct attestation-agent → verifier-CLI flow — with the reason.
- Document how expected launch measurements will be derived and recorded when real hardware arrives, so SNP day is value-recording, not design work.
- Idempotent bring-up/teardown scripts.
Deliverables
- Manifests + version manifest + scripts + the recorded topology decision + a green dev-mode E2E.
Expected outcome
#8536 on real metal is a config apply plus measurement recording — zero net-new design or code.
Context
Part of the attested-evaluation epic (#8534). #8536 stands up the CoCo runtime class on SNP metal; everything about that stack except the TEE itself can be built and exercised now using CoCo's no-TEE/sample runtime path on existing hardware or a VM. This issue produces the manifests, pinned versions, and decisions so that #8536 becomes "apply the same manifests on the metal and record real measurements."
Requirements
Deliverables
Expected outcome
#8536 on real metal is a config apply plus measurement recording — zero net-new design or code.