Skip to content

refactor!: attestation serves the founding harvest; summit keys via setup units - #78

Merged
samlaf merged 3 commits into
seismicfrom
sl/sei-781-feat-the-attestation-service-serves-the-founding-harvest-and
Oct 6, 2026
Merged

samlaf merged 3 commits into
seismicfrom
sl/sei-781-feat-the-attestation-service-serves-the-founding-harvest-and

Conversation

@samlaf

@samlaf samlaf commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SEI-781. Image side of SeismicSystems/enclave#285.

Three commits, merged separately as a rebase merge:

  1. summit-key-holder retires: the attestation service serves the founding
    harvest from boot and is the only TPM user; summit.target groups
    summit-keygen → summit-persist → summit.
  2. /persistent/conf becomes root-only /persistent/nginx.
  3. Module readme rewritten around units, users and directories; top-level
    README follows.

samlaf added 3 commits October 6, 2026 13:59
…lder retires

Fixes SEI-781.

summit-key-holder, the enclave daemon that generated summit's keys at
boot, served them with a quote on :7879 and wrote the keystore once LUKS
opened, is gone. Two things replace it.

The attestation service starts at boot and serves the founding harvest
on :7879 itself
(SeismicSystems/enclave#285), so it is the only
process that opens the TPM. The summit user leaves the tpm group: any
process that can quote arbitrary report_data can have a peer wrap
root_key to a key of its own.

summit.target groups three units:

- summit-keygen, a oneshot at boot: `summit keys generate
  --no-overwrite` into /run/seismic/summit/keys, and the public halves
  from `summit keys show --json` into public-keys.json for the harvest.
- summit-persist, a oneshot after persistent-luks-setup: copies the
  tmpfs keys into /persistent/summit/keys on first boot, or confirms the
  keystore on a reboot, then republishes the public keys from it.
- summit, which now only reads its keystore.

attestation.service no longer waits for tdx-init or the custodian. It
reads its peers once tdx-init's done marker appears and retries the
custodian socket, so it only pulls them in with Wants=. An explicit
restart of the custodian therefore no longer restarts it; SEI-777 is
where a custodian restart's behaviour gets decided.

The enclave pin moves to 0ac3a6a. The summit pin moves to 299d8d7 for
`keys show --json` (SeismicSystems/summit#466).

Design: https://github.com/SeismicSystems/seismic/blob/main/docs/tee/architecture.md#one-process-opens-the-tpm
tdx-init writes nothing under /persistent; its config lives on tmpfs in
/run/seismic/conf. All that /persistent/conf held was nginx's site
config and certbot's state, both written as root by nginx-ssl-setup and
certbot-renew. The dir is now named for what it holds and is 0700
root:root.

tdx-init also leaves the conf group: it owns /run/seismic/conf, whose
setgid bit gives every file it writes group conf.

A node that reboots onto this image with an existing volume requests a
new certificate and leaves /persistent/conf behind.
The module readme's ASCII boot chain restated the unit files' After= and
Requires= lines. It now links the boot order in the seismic architecture
doc and keeps what only this repo can say: which user runs each unit,
what each group grants, and who writes and reads each runtime and
persistent directory.

The top-level README follows. Its component table and "Where to look
next" list give way to a pointer to the module readme, and the Azure
measurements doc is linked next to the measurement files. /attestation
is marked as meant to be public, since it proxies :7878, which peers
already reach from anywhere. The getPurposeKeys warning goes: reth
fetches its keys from the custodian socket and the method no longer
exists. node-template.conf's split TODO says the same.
@samlaf
samlaf requested a review from a team as a code owner October 6, 2026 18:03
@linear-code

linear-code Bot commented Oct 6, 2026

Copy link
Copy Markdown

SEI-781

Comment on lines +19 to +20
# Pointing to https://github.com/SeismicSystems/summit/pull/466 until it gets merged
git_reference: 299d8d7c5831af64f292ea060846ba56b044e7cf

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO: don't want to block on this so will merge, but we should update this reference once SeismicSystems/summit#466 merges

@samlaf
samlaf merged commit 9c7b775 into seismic Oct 6, 2026
5 checks passed
@samlaf
samlaf deleted the sl/sei-781-feat-the-attestation-service-serves-the-founding-harvest-and branch October 6, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant