Provision
Provision a new VM at runtime: record its root CA identity and issue storage secrets.
Only 1.4.0+ VMs reach this route (it is behind require_cvm_proxy), and every one of them signs, so require_hotkey_auth demands a proven hotkey at the door -- no backwards-compatible "unsigned is acceptable" case exists here, unlike boot attestation. The proven identity is what the rc gate in verify_quote is given.
The RTMR3-attested runtime entry point for new VMs (supersedes /luks/attest going forward). The VM presents its per-boot root CA as the mTLS client cert; the quote's REPORTDATA binds SHA256(that cert's pubkey), so the same cert_hash check that guards /luks/attest also proves CA possession — no bespoke quote logic is needed. require_luks_quote_nonce validates and consumes the runtime nonce; the handler verifies the quote (signature + all RTMR measurements incl. RTMR3), records server.vm_root_ca_cert (idempotent), and returns rotated passphrases, the k3s encryption key, and a confirm nonce.
Path parameters
Headers
Request body
Response
Successful Response
Changes
Changed in 4 of the 11 revisions of this API.132
- ●
deleted the
headerrequest parameterX-Chutes-Noncerequest-parameter-removed
- ●
deleted the
headerrequest parameterX-Chutes-Signaturerequest-parameter-removed
- ●
deleted the
headerrequest parameterX-Operator-Signaturerequest-parameter-removed
This revision also has 2 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ●
- ○
endpoint added
endpoint-added
- ○
- ▲
api path removed without deprecation
api-path-removed-without-deprecation
This revision also has 97 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ▲
- ○
endpoint added
endpoint-added
- ○