PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/25f15e7e.21388cd0.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:42:29 UTC 10,993 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["1402"],{504260:function(e,t,s){s.r(t),s.d(t,{frontMatter:()=>i,toc:()=>l,default:()=>u,metadata:()=>o,assets:()=>a,contentTitle:()=>d});var o=JSON.parse('{"id":"clusters/edge/trusted-boot/trusted-boot","title":"Trusted Boot","description":"Learn about Trusted Boot.","source":"@site/docs/docs-content/clusters/edge/trusted-boot/trusted-boot.md","sourceDirName":"clusters/edge/trusted-boot","slug":"/clusters/edge/trusted-boot/","permalink":"/clusters/edge/trusted-boot/","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/clusters/edge/trusted-boot/trusted-boot.md","tags":[{"inline":true,"label":"edge","permalink":"/tags/edge"}],"version":"current","lastUpdatedAt":1777826507000,"sidebarPosition":10,"frontMatter":{"sidebar_label":"Trusted Boot","title":"Trusted Boot","description":"Learn about Trusted Boot.","hide_table_of_contents":false,"sidebar_position":10,"tags":["edge"]},"sidebar":"docSidebar","previous":{"title":"Deployment Lifecycle","permalink":"/clusters/edge/edge-native-lifecycle"},"next":{"title":"Trusted Boot Keys","permalink":"/clusters/edge/trusted-boot/keys/"}}'),r=s(474848),n=s(884429);let i={sidebar_label:"Trusted Boot",title:"Trusted Boot",description:"Learn about Trusted Boot.",hide_table_of_contents:!1,sidebar_position:10,tags:["edge"]},d,a={},l=[{value:"Why Do You Need Trusted Boot?",id:"why-do-you-need-trusted-boot",level:2},{value:"Limitations",id:"limitations",level:2},{value:"Next Steps",id:"next-steps",level:2},{value:"Resources",id:"resources",level:2}];function c(e){let t={a:"a",h2:"h2",img:"img",li:"li",p:"p",ul:"ul",...(0,n.R)(),...e.components},{PartialsComponent:o}=t;return o||function(e,t){throw Error("Expected "+(t?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("PartialsComponent",!0),(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.p,{children:"Trusted Boot is a security feature supported by Palette Edge available on Edge devices with supported hardware and\nfirmware. Trusted Boot consists of the following security measures:"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{alt:"High level description diagram for Trusted Boot",src:s(329548).A+"",width:"2760",height:"376"})}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:"Full Disk Encryption (FDE): Encryption of all persistent partitions of the disk drive. The purpose of FDE is to\nprotect data stored on the disk from unauthorized access if the boot process was tempered with."}),"\n",(0,r.jsx)(t.li,{children:"Secure boot: A security measure that ensures only properly signed and authenticated software is allowed to operate\nduring the boot process of a device."}),"\n",(0,r.jsxs)(t.li,{children:["Measured boot. A security feature that works by measuring each component of the boot process and recording these\nmeasurements in a\n",(0,r.jsx)(t.a,{href:"https://www.intel.com/content/www/us/en/learn/what-is-a-trusted-platform-module.html",children:"Trusted Platform Module (TPM)"}),".\nOnly when it receives measurements with a valid signature does the TPM release the key to decrypt encrypted content."]}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"Together, these measures allow Trusted Boot to ensure the authenticity of the boot processes that are allowed to operate\non your Edge device. Only when the boot process can be verified does the TPM release the key to decrypt the encrypted\ncontent, and the sensitive data is not accessible if the boot process is tempered with."}),"\n",(0,r.jsx)(t.h2,{id:"why-do-you-need-trusted-boot",children:"Why Do You Need Trusted Boot?"}),"\n",(0,r.jsx)(t.p,{children:"Edge devices are often deployed in locations with minimal security and high traffic, such as restaurants and coffee\nshops, and are susceptible to physical attacks. If an attacker is able to inject malware into the Edge host through a\nphysical attack, it has the potential to compromise the security of your operations."}),"\n",(0,r.jsx)(t.p,{children:"Trusted Boot allows you to be confident that all software that is allowed to operate on your Edge hosts is authenticated\nsoftware verified through cryptographic signatures. In the event that an Edge device is lost or stolen, the TPM will not\nrelease the key to decrypt the disk encryption if the boot process is tampered with, ensuring your user data remains\nencrypted."}),"\n",(0,r.jsx)(t.h2,{id:"limitations",children:"Limitations"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsx)(t.p,{children:"Trusted Boot is only supported in environments that use Ubuntu 24.04 as the OS and RKE2 or K3s as the Kubernetes\ndistribution."}),"\n"]}),"\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsx)(o,{category:"cluster
1s-edge",name:"uki-kairos-limitation"}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(t.h2,{id:"next-steps",children:"Next Steps"}),"\n",(0,r.jsx)(t.p,{children:"To get started with Trusted Boot, we recommend you start by familiarizing yourself with the concepts related to Trusted\nBoot, especially the keys used by Trusted Boot and how to manage them. In addition, Trusted Boot has additional hardware\nrequirements compared with Edge hosts that do not have workloads with Trusted Boot. You should ensure that you use Edge\nhosts that meet the minimum hardware requirements."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/keys/",children:"Trusted Boot Keys"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/keys/key-management",children:"Key Management"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/hardware-requirements#trusted-boot",children:"Hardware Requirements"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"After understanding the core concepts, you can proceed to generate the keys that will be used by your Edge host. You\nneed to start by exporting the existing keys on your Edge host and then use those exported keys to generate new keys to\nbe used by Trusted Boot. You can generate keys using a self-signed certificate, or an existing Certificate Authority\n(CA)."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/keys/export-keys",children:"Export Factory Keys"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/keys/generate-keys",children:"Generate Trusted Boot Keys"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"With the keys ready, you can proceed to build the necessary Edge artifacts to install Palette on your Edge host and\nprovision your cluster. The EdgeForge process with Trusted Boot is similar to the EdgeForge process without Trusted\nBoot. We recommend you become familiar with the EdgeForge workflow first before building Edge artifacts with Trusted\nBoot enabled."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/edgeforge-workflow/",children:"EdgeForge Workflow without Trusted Boot"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/edgeforge/",children:"EdgeForge Workflow with Trusted Boot"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"After you build the artifacts, you should check the boot size limit of your Edge host before installing Palette on your\nEdge host. Trusted Boot uses the Unified Kernel Image (UKI), which is a single file that encompasses the Operating\nSystem (OS) and other needed bits in order to boot the full system. As a result, the Extensible Firmware Interface (EFI)\nfile, which contains the UKI, can grow quite large and can pose a limitation depending on your hardware conditions."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/edgeforge/check-efi-limit",children:"Check Device Boot Limit"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"If you find that the EFI file inside the EdgeForge artifacts is bigger than your boot limit, you may need to either\nchoose a device with a higher boot limit or decrease the size of the EFI file. One way to decrease the EFI file size is\nto avoid installing software packages to the OS image and instead use static binaries of the packages you need."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/edgeforge/add-extra-content",children:"Add Static Binaries to Persistent Partition"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"Having ensured that your hardware meets the boot size requirement, you can proceed to install Palette Edge on your Edge\nhost. The installation process is similar to the regular installation workflow, but requires a few additional steps to\nprepare the Edge host for secure boot key enrollment."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/deployment-day2/install",children:"Installation with Trusted Boot"})}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"After installation, the registration process and the process to create a cluster from your Edge host are identical to\nEdge hosts without Trusted Boot. The upgrade process, however, requires you to use the same keys to build new provider\nimages."}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/site-deployment/site-installation/edge-host-registration",children:"Edge Host Registration"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/site-deployment/cluster-deployment",children:"Create Cluster Definition"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/deployment-day2/upgrade-cluster",children:"Upgrade Cluster with Trusted Boot"})}),"\n"]}),"\n",(0,r.jsx)(t.h2,{id:"resources",children:"Resources"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/keys/",children:"Keys"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/edgeforge/",children:"EdgeForge"})}),"\n",(0,r.jsx)(t.li,{children:(0,r.jsx)(t.a,{href:"/clusters/edge/trusted-boot/deployment-day2/",children:"Deployment and Day-2 Operations"})}),"\n"]})]})}function u(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(c,{...e})}):c(e)}},329548:function(e,t,s){s.d(t,{A:()=>
1o});let o=s.p+"assets/images/clusters_edge_trusted-boot_highlevel-b6d3343f3cf5cdaa722f49c5ce667c68.webp"},884429:function(e,t,s){s.d(t,{R:()=>i,x:()=>d});var o=s(296540);let r={},n=o.createContext(r);function i(e){let t=o.useContext(n);return o.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function d(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:i(e.components),o.createElement(n.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.