Skip to main content

TEE stacks (short)

What it is​

TEE = hardware-isolated execution so host OS / hypervisor / admin can’t freely read or tamper with memory in use.

TEE stack = hardware → isolation → runtime/LibOS → orchestration → attestation (prove measured code before releasing keys).

Three trust layers (don’t mix)​

LayerQuestionExamples
ArtifactWho signed this image? Untampered?Cosign, AWS Signer + Notation
Process / supply chainWhat did the build do?in-toto, SLSA, Runtime Trace predicates
Confidential runtimeCan host root snoop or swap code in use?Nitro Enclaves, SEV-SNP, TDX, SGX + CoCo/Gramine
  • Cosign ≈ Signer. Not an open-source Nitro.
  • Open “Nitro-like” idea = TEE/confidential compute (SEV-SNP/TDX + CoCo, etc.), not Sigstore.

Attestation ≠ attestation​

Cosign / in-totoTEE
Signatures & predicates about build/artifactHardware quote/PCR about code running now
“Who signed / what did CI do?”“Is this enclave measurement expected before KMS gives the key?”

Learn path (short)​

  1. Concepts: data-in-use, attestation loop (measure → attest → verify → release secret) — Confidential Computing Consortium, Nitro Enclaves docs
  2. Hardware map: SEV-SNP, TDX, SGX, Nitro Enclaves (compare, don’t memorize every register)
  3. Cloud-native entry: Confidential Containers
  4. Hands-on (pick one): Nitro hello-world + PCRs + KMS, or CoCo hello-world on SNP/TDX

Skip starting on SGX+Gramine day one.