pkg/

directory
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 23, 2026 License: AGPL-3.0

Directories

Path Synopsis
Package allowlist defines the CDS-served image allowlist and its deterministic canonical serialization.
Package allowlist defines the CDS-served image allowlist and its deterministic canonical serialization.
Package allowlistclient is the HTTP client for the CDS allowlist API.
Package allowlistclient is the HTTP client for the CDS allowlist API.
Package certutil provides common helper functions shared across the ratls project: serial number generation, fingerprinting, PEM encoding, and more.
Package certutil provides common helper functions shared across the ratls project: serial number generation, fingerprinting, PEM encoding, and more.
Package earsigner manages the EAR token-signing key lifecycle with overlap-based rotation and JWKS serving.
Package earsigner manages the EAR token-signing key lifecycle with overlap-based rotation and JWKS serving.
Package initdata builds and reads the kata init-data document c8s delivers into a confidential guest.
Package initdata builds and reads the kata init-data document c8s delivers into a confidential guest.
Package issuerapi defines the wire types for the CDS signing/handoff HTTP API.
Package issuerapi defines the wire types for the CDS signing/handoff HTTP API.
Package jwks wraps go-jose to produce JWK Sets from ECDSA public keys.
Package jwks wraps go-jose to produce JWK Sets from ECDSA public keys.
Package operatorauth implements the operator-credential scheme that authorizes c8s allowlist mutations (POST/PUT/DELETE /allowlist).
Package operatorauth implements the operator-credential scheme that authorizes c8s allowlist mutations (POST/PUT/DELETE /allowlist).
Package overenc implements the c8s-verify post-quantum over-encryption channel that terminates inside the Load Balancer's TEE.
Package overenc implements the c8s-verify post-quantum over-encryption channel that terminates inside the Load Balancer's TEE.
Package ratls implements RA-TLS (Remote Attestation TLS) for AMD SEV-SNP and Intel TDX.
Package ratls implements RA-TLS (Remote Attestation TLS) for AMD SEV-SNP and Intel TDX.
cdsclient
Package cdsclient implements certificate provisioning via the CDS attestation-api.
Package cdsclient implements certificate provisioning via the CDS attestation-api.
Package resources defines the c8s resource path constants used in the EAR-driven access-control model: a resourceMap maps each attested launch measurement to the list of resources that measurement is authorised for.
Package resources defines the c8s resource path constants used in the EAR-driven access-control model: a resourceMap maps each attested launch measurement to the list of resources that measurement is authorised for.
Package runtimemeasure pins the c8s conventions for runtime measurement: what a guest extends into its runtime measurement register after launch, and in what order.
Package runtimemeasure pins the c8s conventions for runtime measurement: what a guest extends into its runtime measurement register after launch, and in what order.
Package snpmeasure computes the SEV-SNP launch measurement (launch digest) of a QEMU guest offline, from the firmware and boot artifacts, before the guest is ever started.
Package snpmeasure computes the SEV-SNP launch measurement (launch digest) of a QEMU guest offline, from the firmware and boot artifacts, before the guest is ever started.
Package tdxmeasure computes the Intel TDX build-time measurement (MRTD) of a kata confidential guest offline, from the TDVF firmware image, before the guest is ever started.
Package tdxmeasure computes the Intel TDX build-time measurement (MRTD) of a kata confidential guest offline, from the TDVF firmware image, before the guest is ever started.
Package workloadclaims implements the admission-inventory API: the component that admitted a pod's containers (nri-image-policy on node-CVM, policy-monitor in a kata guest) is the arbiter of both what runs in a pod sandbox and which sandbox a process belongs to.
Package workloadclaims implements the admission-inventory API: the component that admitted a pod's containers (nri-image-policy on node-CVM, policy-monitor in a kata guest) is the arbiter of both what runs in a pod sandbox and which sandbox a process belongs to.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL