Manifest types

Types describing the deployment manifest that remote attestation is verified against. A manifest is obtained from verify() or the manifest accessor.

Manifest

Manifest describing the Privatemode deployment.

PoliciesRecord<string, ManifestPolicy>

Policies keyed by their hash.

ReferenceValuesReferenceValues

Reference values for attestation verification.

SeedshareOwnerPubKeysstring[]

Public keys of seedshare owners.

ManifestPolicy

Policy entry for a workload in the manifest.

SANsstring[]required

Subject Alternative Names for the workload's certificate.

WorkloadSecretIDstringrequired

Identifier for the workload's secret.

Rolestring

Optional role assigned to the workload.

ReferenceValues

Reference values for attestation verification.

snpSNPReferenceValue[]

SNPReferenceValue

SNP reference value entry.

ProductNamestringrequired

TrustedMeasurementstringrequired

MinimumTCBMinimumTCBrequired

GuestPolicyGuestPolicyrequired

PlatformInfoPlatformInforequired

AllowedChipIDsstring[]required

MinimumTCB

Minimum TCB (Trusted Computing Base) version requirements.

BootloaderVersionnumberrequired

TEEVersionnumberrequired

SNPVersionnumberrequired

MicrocodeVersionnumberrequired

GuestPolicy

Guest policy settings for SNP.

SMTbooleanrequired

MigrateMAbooleanrequired

Debugbooleanrequired

CXLAllowedbooleanrequired

PageSwapDisablebooleanrequired

PlatformInfo

Platform information for SNP.

SMTEnabledbooleanrequired

ECCEnabledbooleanrequired

AliasCheckCompletebooleanrequired