Verify Boot Attestation
Verify boot attestation and return LUKS passphrase.
Both VM generations reach this route, so the hotkey proof is EXTRACTED rather than required: a presented signature is verified here and 401s if it does not hold, but its absence is left for the handler to judge once the quote names the attested image. See process_boot_attestation, which requires a proof from any image whose measured initramfs ships the signer.
Verifies the TDX quote against the expected boot measurements and returns the LUKS passphrase for disk decryption if valid. For VMs >= 1.3.0 it also returns a luks_quote_nonce for the following runtime call (POST /provision on 1.4.0+, POST /luks/attest on 1.3.x); for 1.4.0+ it additionally returns root_next + root_confirm_nonce and the VM's ephemeral auth SS58.
Headers
Request body
Response
Successful Response