Implementation · Cove · Draft

Evidence & limits

On this page

R2Demonstrated for composing owner-approved confidential workflow stages on Intel TDX

Public source and documentation describe an end-to-end implementation on commercial confidential hardware.

  • R1 met: the reference documentation defines artifacts, workflow manifests, certificates and trust assumptions 1.
  • R2 met through a public reference implementation and documented end-to-end demo on Phala's Intel TDX stack. The demo exercises owner approval, attested release and dependency certificates 1.
  • R3 not met: reference code and a demo do not establish a production-grade evaluation workflow or another party's reliance on its result 1.

Assessed use: composing owner-approved confidential workflow stages on Intel TDX

Rubric assessment

Gaps to the next level
  • A production-grade, available confidential evaluation workflow, or another party's documented reliance on its results.

Assessed 2026-10-08 against rubric v1.1.

Evidence

  • The public repository includes the compiler, command-line interface, runtime components, storage server and documentation. The reference architecture uses Intel TDX through Phala's dstack 1.
  • The developers document a demo exercising static and dynamic assets, two owners, approval rules, dependency certificates, preconditions and a long-running attested service 1.
  • The storage server, routing layer and orchestration are outside the integrity trust root. Verification rests on the manifests, pinned components and attestation evidence 1.

Limitations

Cove trusts the hardware attestation path, Docker's enforcement, pinned first-party components and human review of public code. Compromise of the Docker daemon, guest host kernel or trusted TEE stack defeats its guarantees 1. Published bundles lack publisher signatures, and some trusted components use host networking. The developers distinguish demo key release from production attested key release 1.

Known flaws

Blockers

  • Docker policy cannot prove that arbitrary guest workloads cannot generate quotes when quote channels are globally exposed.

  • The production workflow depends on owners reviewing manifests, allow rules and provisioning code.

Search

Full search page