kairos-io / kairos

The immutable Linux meta-distribution for edge Kubernetes.
https://kairos.io
Apache License 2.0
1.16k stars 97 forks source link

spike: UKI Remote boot attestation with KMS #2988

Open Itxaka opened 2 weeks ago

Itxaka commented 2 weeks ago

We would like to investigate how we can port the KMS to UKI scenarios.

High level scenario:

Reference

https://www.redhat.com/en/blog/attestation-confidential-computing https://docs.system-transparency.org/st-1.1.0/docs/selected-topics/remote-attestation/ https://kairos.io/docs/advanced/partition_encryption/#discoverable-key-management-server-kms

mudler commented 2 weeks ago

Seems we basically had this around already: https://github.com/kairos-io/kairos/issues/2166