Expand description
Hardware-agnostic attestation providers.
Each supported TEE (AWS Nitro, AMD SEV-SNP, Intel TDX, …) implements
AttestationProvider. detect probes the machine at runtime and returns the provider
matching the hardware we are running on; by_name selects one explicitly.
Backends are gated by additive Cargo features (nitro, sev-snp, tdx, mock), so a single
binary can support several of them.
Re-exports§
pub use nitro::NsmSession;pub use mock::MockSession;
Modules§
- eat
- RFC 9711 Entity Attestation Token (EAT) data model.
- mock
- Mock provider for local development and CI where no TEE hardware exists.
- nitro
- AWS Nitro Security Module (NSM) provider.
- nitro_
doc - Nitro attestation-document helpers shared by the real (
nitro) andmockproviders: COSE_Sign1 payload extraction, parsing, mock document creation and EAT wrapping.
Enums§
- Attestation
Error - Errors produced by any attestation provider.
Constants§
- PROVIDER_
ENV - Environment variable that forces a specific provider (see
by_name).
Traits§
- Attestation
Provider - A source of attestation evidence backed by a specific TEE.