Dstack-TEE / Dstack-TEE/dstack-examples

Dstack Governor - dev tools for the Onchain-KMS

未关闭
#17 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Python
星标
27
派生
26
平均合并
1 小时 25 分钟
30 天内合并 PR
7

描述

We are missing smart contract templates and release management tools for maintaining production TEE applications using an [On-chain KMS .](https://github.com/Dstack-TEE/dstack/tree/kms-onchain/kms)

The purpose of on-chain KMS is to enable TEEs to use smart contract security processes. Without this, the application developer is a single point of failure, since they can apply harmful software updates.

1. On the **smart contract side,** we can get pretty far just by copying existing patterns from OpenZeppelin Bravo. Basically the process consists of a) a notice period, and b) a security council that can veto or delay the proposal.

2. On the **DevEx side,** we need command line tools and/or a web interface to make proposals, and for a security council to review and reject updates if needed.

3. **Documentation and guidance for the social layer**, including the upgrade review process that the security council is supposed to oversee.

References:
- [How to set up on-chain governance](https://docs.openzeppelin.com/contracts/5.x/governance)
- [From Stage 0 to Stage 1: Security Council Best Practices in Rollup Governance](https://blog.openzeppelin.com/security-council-best-practices-guide)

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。