Dstack-TEE / Dstack-TEE/dstack
Tracking: AWS EC2 NitroTPM attestation platform support
- Dominant language
- Rust
- Stars
- 544
- Forks
- 96
- Avg merge
- 17h 57m
- Merged PRs (30d)
- 117
Description
Tracks the two PRs that add the **AWS EC2 NitroTPM** attestation platform to dstack (account-admin-untrusted threat model).
## PRs
- **Dstack-TEE/dstack#753** — core implementation: NitroTPM attestation-document parsing/verification, PCR14 launch + PCR23 runtime measurement, KMS key release without AWS KMS, verifier + `auth-simple`/`auth-eth` support, and SDK updates. Base `master`, one squashed commit (`504e3420`).
- **Dstack-TEE/meta-dstack#79** — Yocto layer: the `dstack-aws` kernel fragment (NVMe/ENA root, EFI/GPT, serial console, TPM CRB) and the `tpm2-tss` guest build dep. Base `main` (`a1aa04e`). **Depends on #753.**
## Status
Both are rebased onto their latest base and **MERGEABLE**. On #753 every functional CI job is green (rust-checks, sdk-tests, kms, verifier, gateway, prek, reuse-lint); meta#79 CI is green.
## Design notes for reviewers
- **Integrates like AMD SEV-SNP, not with bespoke surface.** A verified NitroTPM attestation has no TDX/SNP-style TCB surface, so it is normalized to `tcbStatus = "UpToDate"` and passes the **unchanged** on-chain contract — no AWS-specific on-chain field.
- **AWS key release is opt-in:** `aws_nitro_tpm_key_release = false` by default in `kms.toml`, mirroring `sev_snp_key_release` (fail-closed for the new, weaker mode).
- **App is trusted post-launch, exactly as on TDX/SNP** — no compose-security filter or device sandbox; integrity rests on measurement + non-resettable PCR14. Rationale in `docs/aws-attested-instance-security-evaluation.md`.
- `GetPlatform` was folded into `AppInfo.attestation` rather than adding a new endpoint.
## Before merge
- [ ] Merge order: **#753 first**, then bump the submodule and merge meta#79.
- [ ] Dismiss the CodeQL alerts flagged on #753's diff — they are **pre-existing, in files this PR doesn't touch** (surfaced only because the squashed diff is large). Notably `sodiumbox/src/lib.rs:62` "hard-coded cryptographic value" is the HSalsa20 zero nonce, i.e. the correct NaCl `crypto_box` construction (false positive); the rest are pre-existing in `ra-rpc`, `http-client`, and `sdk/go/ratls`.
## Follow-ups (post-merge, optional)
- Share the X25519+AES-GCM envelope (`encrypt_for_x25519_recipient` in KMS + `dh_decrypt` in the guest) via a small lib crate — deferred because `dstack-util` is a binary crate.
- Confirm whether the `tpm2-tss` build dep in meta#79 is actually needed (the guest drives the TPM via the in-tree `tpm2` crate over `/dev/tpmrm0`).
Contributor guide
Research direction
Start by reviewing Dstack-TEE/dstack#753 and Dstack-TEE/meta-dstack#79, including docs/aws-attested-instance-security-evaluation.md and the listed CI results. Done means merging #753 first, bumping the submodule for meta#79, and dismissing the specified pre-existing CodeQL alerts.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, rust
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 20/100