Directories
¶
| Path | Synopsis |
|---|---|
|
Package allowlist defines the CDS-served image allowlist and its deterministic canonical serialization.
|
Package allowlist defines the CDS-served image allowlist and its deterministic canonical serialization. |
|
Package allowlistclient is the HTTP client for the CDS allowlist API.
|
Package allowlistclient is the HTTP client for the CDS allowlist API. |
|
Package certutil provides common helper functions shared across the ratls project: serial number generation, fingerprinting, PEM encoding, and more.
|
Package certutil provides common helper functions shared across the ratls project: serial number generation, fingerprinting, PEM encoding, and more. |
|
Package earsigner manages the EAR token-signing key lifecycle with overlap-based rotation and JWKS serving.
|
Package earsigner manages the EAR token-signing key lifecycle with overlap-based rotation and JWKS serving. |
|
Package initdata builds and reads the kata init-data document c8s delivers into a confidential guest.
|
Package initdata builds and reads the kata init-data document c8s delivers into a confidential guest. |
|
Package issuerapi defines the wire types for the CDS signing/handoff HTTP API.
|
Package issuerapi defines the wire types for the CDS signing/handoff HTTP API. |
|
Package jwks wraps go-jose to produce JWK Sets from ECDSA public keys.
|
Package jwks wraps go-jose to produce JWK Sets from ECDSA public keys. |
|
Package operatorauth implements the operator-credential scheme that authorizes c8s allowlist mutations (POST/PUT/DELETE /allowlist).
|
Package operatorauth implements the operator-credential scheme that authorizes c8s allowlist mutations (POST/PUT/DELETE /allowlist). |
|
Package overenc implements the c8s-verify post-quantum over-encryption channel that terminates inside the Load Balancer's TEE.
|
Package overenc implements the c8s-verify post-quantum over-encryption channel that terminates inside the Load Balancer's TEE. |
|
Package ratls implements RA-TLS (Remote Attestation TLS) for AMD SEV-SNP and Intel TDX.
|
Package ratls implements RA-TLS (Remote Attestation TLS) for AMD SEV-SNP and Intel TDX. |
|
cdsclient
Package cdsclient implements certificate provisioning via the CDS attestation-api.
|
Package cdsclient implements certificate provisioning via the CDS attestation-api. |
|
Package resources defines the c8s resource path constants used in the EAR-driven access-control model: a resourceMap maps each attested launch measurement to the list of resources that measurement is authorised for.
|
Package resources defines the c8s resource path constants used in the EAR-driven access-control model: a resourceMap maps each attested launch measurement to the list of resources that measurement is authorised for. |
|
Package runtimemeasure pins the c8s conventions for runtime measurement: what a guest extends into its runtime measurement register after launch, and in what order.
|
Package runtimemeasure pins the c8s conventions for runtime measurement: what a guest extends into its runtime measurement register after launch, and in what order. |
|
Package snpmeasure computes the SEV-SNP launch measurement (launch digest) of a QEMU guest offline, from the firmware and boot artifacts, before the guest is ever started.
|
Package snpmeasure computes the SEV-SNP launch measurement (launch digest) of a QEMU guest offline, from the firmware and boot artifacts, before the guest is ever started. |
|
Package tdxmeasure computes the Intel TDX build-time measurement (MRTD) of a kata confidential guest offline, from the TDVF firmware image, before the guest is ever started.
|
Package tdxmeasure computes the Intel TDX build-time measurement (MRTD) of a kata confidential guest offline, from the TDVF firmware image, before the guest is ever started. |
|
Package workloadclaims implements the admission-inventory API: the component that admitted a pod's containers (nri-image-policy on node-CVM, policy-monitor in a kata guest) is the arbiter of both what runs in a pod sandbox and which sandbox a process belongs to.
|
Package workloadclaims implements the admission-inventory API: the component that admitted a pod's containers (nri-image-policy on node-CVM, policy-monitor in a kata guest) is the arbiter of both what runs in a pod sandbox and which sandbox a process belongs to. |
Click to show internal directories.
Click to hide internal directories.