Skip to content

ci(seismic): publish the GCP tarball, GCE image and measurements with each release - #75

Draft
HenryMBaldwin wants to merge 1 commit into
hbai__gcp-firmware-endorsementfrom
hbai__gcp-publish
Draft

HenryMBaldwin wants to merge 1 commit into
hbai__gcp-firmware-endorsementfrom
hbai__gcp-publish

Conversation

@HenryMBaldwin

Copy link
Copy Markdown
Contributor
  • Stacked on chore(gcp): pin enclave requiring Google-endorsed firmware #74.
  • make release-assets also predicts the GCP registers; measurements.gcp-tdx.json joins SHA256SUMS, the build artifact, the attestation and the release.
  • make push-gcp mirrors the tarball to gs://seismic-tee-gcp-images and registers it as the GCE image named by the tag with _ and . as -, idempotent like push-azure.
  • image.json gains a gcp-tdx target: gce_image, tarball_url, measurements, efi_sha256. The CLI's ImageTarget passes the extra fields through.
  • The publish job authenticates to GCP through Workload Identity Federation (GCP_WORKLOAD_IDENTITY_PROVIDER, GCP_SERVICE_ACCOUNT); the header documents the one-time setup, the twin of the Azure block.
  • Dry-run locally on seismic-dev_2026-09-28.9e48a9: release assets and image.json with both targets. The publish job runs only on seismic, so its first run is after merge; the two secrets must exist by then.

@HenryMBaldwin
HenryMBaldwin force-pushed the hbai__gcp-firmware-endorsement branch from ce1f1ee to 6eb7ef3 Compare October 2, 2026 19:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant