Tee dev cleanup (#759)

* build: added scripts for local tee/sgx development
* Improved documentation: move all explanation to one README file
This commit is contained in:
Hendrik Eeckhaut
2025-04-28 14:46:32 +02:00
committed by GitHub
parent 8afb7a4c11
commit 19447aabe5
6 changed files with 186 additions and 83 deletions

View File

@@ -280,7 +280,7 @@ jobs:
crates/notary/server/tee/notary-server.manifest
crates/notary/server/tee/notary-server.manifest.sgx
crates/notary/server/tee/config
crates/notary/server/tee/notary-server-sgx.md
crates/notary/server/tee/README.md
if-no-files-found: error
- name: Attest Build Provenance
@@ -304,24 +304,17 @@ jobs:
CONTAINER_REGISTRY: ghcr.io
if: github.ref == 'refs/heads/dev' || (startsWith(github.ref, 'refs/tags/v') && contains(github.ref, '.'))
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
sparse-checkout: './crates/notary/server/tee/notary-server-sgx.Dockerfile'
- name: Download notary-server-sgx.zip from gramine-sgx job
uses: actions/download-artifact@v4
with:
name: notary-server-sgx.zip
path: ./notary-server-sgx
- name: Create Dockerfile
run: |
cat <<EOF > ./Dockerfile
FROM gramineproject/gramine:latest
WORKDIR /work
COPY ./notary-server-sgx /work
RUN chmod +x /work/notary-server
LABEL org.opencontainers.image.source=https://github.com/tlsnotary/tlsn
LABEL org.opencontainers.image.description="TLSNotary notary server in SGX/Gramine."
ENTRYPOINT ["gramine-sgx", "notary-server"]
EOF
- name: Log in to the Container registry
uses: docker/login-action@v2
with:
@@ -342,7 +335,8 @@ jobs:
push: true
tags: ${{ steps.meta-notary-server-sgx.outputs.tags }}
labels: ${{ steps.meta-notary-server-sgx.outputs.labels }}
file: ./Dockerfile
file: ./crates/notary/server/tee/notary-server-sgx.Dockerfile
build_and_publish_notary_server_image:
name: Build and publish notary server's image
runs-on: ubuntu-latest