feat(kms): add GetAttestationInfo RPC to onboard service #503
+133
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
GetAttestationInfoRPC to the Onboard service that returns the realdevice_id,mr_aggregated,os_image_hash,mr_system, andattestation_modeneeded for on-chain KMS authorizationdevice_id = SHA256(ppid)— unlike the serial log which showsSHA256("") = e3b0c442...due toAttestation<()>having no ppidScreenshot
Onboard web UI on GCP TDX Confidential VM:
Motivation
When onboarding a new KMS instance, operators need to register the correct
device_id,mr_aggregated, andos_image_hashon-chain before the source KMS will authorize key transfer. Previously there was no way to obtain these real values from the KMS itself — the serial log values were incorrect fordevice_id.Test plan
cargo check -p dstack-kmscompiles0xprefix for easy copy to on-chain registration