Repository navigation
refactor!: attestation serves the founding harvest; summit keys via setup units - #78
Merged
samlaf merged 3 commits intoOct 6, 2026
Conversation
…lder retires Fixes SEI-781. summit-key-holder, the enclave daemon that generated summit's keys at boot, served them with a quote on :7879 and wrote the keystore once LUKS opened, is gone. Two things replace it. The attestation service starts at boot and serves the founding harvest on :7879 itself (SeismicSystems/enclave#285), so it is the only process that opens the TPM. The summit user leaves the tpm group: any process that can quote arbitrary report_data can have a peer wrap root_key to a key of its own. summit.target groups three units: - summit-keygen, a oneshot at boot: `summit keys generate --no-overwrite` into /run/seismic/summit/keys, and the public halves from `summit keys show --json` into public-keys.json for the harvest. - summit-persist, a oneshot after persistent-luks-setup: copies the tmpfs keys into /persistent/summit/keys on first boot, or confirms the keystore on a reboot, then republishes the public keys from it. - summit, which now only reads its keystore. attestation.service no longer waits for tdx-init or the custodian. It reads its peers once tdx-init's done marker appears and retries the custodian socket, so it only pulls them in with Wants=. An explicit restart of the custodian therefore no longer restarts it; SEI-777 is where a custodian restart's behaviour gets decided. The enclave pin moves to 0ac3a6a. The summit pin moves to 299d8d7 for `keys show --json` (SeismicSystems/summit#466). Design: https://github.com/SeismicSystems/seismic/blob/main/docs/tee/architecture.md#one-process-opens-the-tpm
tdx-init writes nothing under /persistent; its config lives on tmpfs in /run/seismic/conf. All that /persistent/conf held was nginx's site config and certbot's state, both written as root by nginx-ssl-setup and certbot-renew. The dir is now named for what it holds and is 0700 root:root. tdx-init also leaves the conf group: it owns /run/seismic/conf, whose setgid bit gives every file it writes group conf. A node that reboots onto this image with an existing volume requests a new certificate and leaves /persistent/conf behind.
The module readme's ASCII boot chain restated the unit files' After= and Requires= lines. It now links the boot order in the seismic architecture doc and keeps what only this repo can say: which user runs each unit, what each group grants, and who writes and reads each runtime and persistent directory. The top-level README follows. Its component table and "Where to look next" list give way to a pointer to the module readme, and the Azure measurements doc is linked next to the measurement files. /attestation is marked as meant to be public, since it proxies :7878, which peers already reach from anywhere. The getPurposeKeys warning goes: reth fetches its keys from the custodian socket and the method no longer exists. node-template.conf's split TODO says the same.
samlaf
commented
Oct 6, 2026
Comment on lines
+19
to
+20
| # Pointing to https://github.com/SeismicSystems/summit/pull/466 until it gets merged | ||
| git_reference: 299d8d7c5831af64f292ea060846ba56b044e7cf |
Contributor
Author
There was a problem hiding this comment.
TODO: don't want to block on this so will merge, but we should update this reference once SeismicSystems/summit#466 merges
samlaf
deleted the
sl/sei-781-feat-the-attestation-service-serves-the-founding-harvest-and
branch
October 6, 2026 18:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes SEI-781. Image side of SeismicSystems/enclave#285.
Three commits, merged separately as a rebase merge:
harvest from boot and is the only TPM user; summit.target groups
summit-keygen → summit-persist → summit.
README follows.