Tracking: AWS EC2 NitroTPM attestation platform support
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 20/100
Hướng nghiên cứu
Bắt đầu bằng việc xem xét Dstack-TEE/dstack#753 và Dstack-TEE/meta-dstack#79, bao gồm docs/aws-attested-instance-security-evaluation.md và các kết quả CI được liệt kê. Được xem là hoàn tất khi trước tiên merge #753, cập nhật submodule cho meta#79 và loại bỏ các cảnh báo CodeQL có từ trước được chỉ định.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Tracks the two PRs that add the AWS EC2 NitroTPM attestation platform to dstack (account-admin-untrusted threat model).
PRs
- Dstack-TEE/dstack#753 — core implementation: NitroTPM attestation-document parsing/verification, PCR14 launch + PCR23 runtime measurement, KMS key release without AWS KMS, verifier +
auth-simple/auth-ethsupport, and SDK updates. Basemaster, one squashed commit (504e3420). - Dstack-TEE/meta-dstack#79 — Yocto layer: the
dstack-awskernel fragment (NVMe/ENA root, EFI/GPT, serial console, TPM CRB) and thetpm2-tssguest build dep. Basemain(a1aa04e). Depends on #753.
Status
Both are rebased onto their latest base and MERGEABLE. On #753 every functional CI job is green (rust-checks, sdk-tests, kms, verifier, gateway, prek, reuse-lint); meta#79 CI is green.
Design notes for reviewers
- Integrates like AMD SEV-SNP, not with bespoke surface. A verified NitroTPM attestation has no TDX/SNP-style TCB surface, so it is normalized to
tcbStatus = "UpToDate"and passes the unchanged on-chain contract — no AWS-specific on-chain field. - AWS key release is opt-in:
aws_nitro_tpm_key_release = falseby default inkms.toml, mirroringsev_snp_key_release(fail-closed for the new, weaker mode). - App is trusted post-launch, exactly as on TDX/SNP — no compose-security filter or device sandbox; integrity rests on measurement + non-resettable PCR14. Rationale in
docs/aws-attested-instance-security-evaluation.md. GetPlatformwas folded intoAppInfo.attestationrather than adding a new endpoint.
Before merge
- Merge order: #753 first, then bump the submodule and merge meta#79.
- Dismiss the CodeQL alerts flagged on #753's diff — they are pre-existing, in files this PR doesn't touch (surfaced only because the squashed diff is large). Notably
sodiumbox/src/lib.rs:62"hard-coded cryptographic value" is the HSalsa20 zero nonce, i.e. the correct NaClcrypto_boxconstruction (false positive); the rest are pre-existing inra-rpc,http-client, andsdk/go/ratls.
Follow-ups (post-merge, optional)
- Share the X25519+AES-GCM envelope (
encrypt_for_x25519_recipientin KMS +dh_decryptin the guest) via a small lib crate — deferred becausedstack-utilis a binary crate. - Confirm whether the
tpm2-tssbuild dep in meta#79 is actually needed (the guest drives the TPM via the in-treetpm2crate over/dev/tpmrm0).
- Ngôn ngữ chính
- Rust
- Star
- 551
- Fork
- 97
- Merge trung bình
- 19 giờ 22 phút
- Pull request đã merge (30 ngày)
- 109
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của Dstack-TEE/dstack
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
Dstack-TEE/dstack#1301 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
Dstack-TEE/dstack#1300 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Dstack-TEE/dstack#1299 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
Dstack-TEE/dstack#1298 ·
-
P0
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
Dstack-TEE/dstack#1297 ·
Tất cả issue của Dstack-TEE/dstack
Issue tương tự
-
Replayed reasoning items send "content": null, which the Responses API schema does not permit Đang mởbug CLI custom-model
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
rust-bitcoin/rust-bitcoin#6930 · 1 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
fulcrumgenomics/ferro-hgvs#2251 ·
-
Missing examples for `Allocator` Đang mởA-allocators A-docs C-enhancement T-libs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100