Verification flow
- Verify the direct model’s Intel TDX quote first.
- Use the raw
info.tcb_info.app_composestring from the direct report. Calculate its SHA-256 hash without parsing or reserializing it, and compare it with the configuration measurement in the verified quote. - Extract every immutable image digest (
@sha256:…) from the matched configuration. - Cryptographically verify provenance for each required digest and confirm that the statement’s subject equals the image digest exactly.
- Apply your policy for repository, build identity, workflow, ref, and source revision.
Relationship to direct attestation
The quote and configuration measurement establish that the configuration text you matched is bound to the verified model report. Provenance establishes that a specific digest satisfies your source and build policy. Use both checks when your application requires a source-to-runtime trust chain.Missing evidence
An unavailable provenance record, including an HTTP404, means the reported digest could not be verified under that policy. It does not by itself identify a security incident.
Fetch a fresh report after a deployment change. If the current evidence still lacks provenance required by your policy, treat that image as unverified.
When requesting help, share only non-sensitive verification metadata: the endpoint, UTC time, model name, signing address,
info.instance_id when present, image name, and full digest. Never include API keys, prompts, or response content.