Guides¶
Task-oriented, step-by-step guides for running sceau — from a first local build against a TPM simulator to a production Kairos host.
-
Build sceau, start a local swtpm simulator, and seal/unseal your first DEK — no hardware TPM required.
-
Wire kube-apiserver to sceau with an
EncryptionConfiguration, then run the migration procedure that re-encrypts existing Secrets. -
Run sceau as a systemd unit on a Kairos host, and bundle the binary into a custom Kairos image.
-
Build and push the distroless image to an internal registry mirror with a single
make docker-imageinvocation — including the Docker Hub gotcha and theIMAGE_REFescape hatch.
Looking to hack on sceau itself?
Building from source, the make targets, and the ADD workflow live under
Developer → Local Development.
Conventions used in these guides¶
- The released image is
ghcr.io/firestoned/sceau, Cosign-signed; see the threat model for verification. - Placeholder hostnames (
bar.foo.io,k0s-node1.example.com) and RFC 5737 IPs are used throughout — substitute your own values. - The KMS socket is
/run/sceau/sceau.sock(mode0600) and the default TCTI isdevice:/dev/tpmrm0; both are overridable via CLI flags.