Operator
Production operation starts with the bring-up document. The agent intentionally fails closed when required gates are missing.
Platform support -- which distributions, firmware and TPM the agent targets, and at what support tier.
Production bring-up -- the full manual reference for fleet hosts, CA, and verifier.
Player install (lota-install) -- the guided, reboot-resumable single-machine path.
Verifier deployment topologies -- single node versus N instances behind a load balancer.
Sizing guide -- agents per verifier, verifiers per Postgres, enrollment bursts and failover behaviour, from measured runs.
Multi-tenancy -- serve several isolated tenants from one verifier with per-tenant bans, policies, and scoped API keys.
Observability -- Prometheus scraping, the reference Grafana dashboard, alert rules, and per-alert runbooks.
Protocol versions -- how the attestation, enrollment and schema surfaces are versioned, and which agent, verifier and CA releases interoperate.
Agent updates and the reboot requirement -- why an agent update needs a cold reboot and a pre-pinned hash.
RPM packages -- the native packages and how to install and bring up the agent.
Container images -- distroless OCI images for the verifier and attestation CA, built with ko.
Verifier Helm chart -- install the HA verifier on Kubernetes.
COPR repository -- install the packages from the Fedora COPR build service.
Signed dnf repository -- sign the packages and serve them from a dnf repository.
Fleet CLI (lota-fleet) -- drive the verifier's monitoring API: revocations, bans, re-anchor, client removal, logs.
Monitoring API reference -- the REST endpoint contract the fleet CLI and custom tooling consume.
Related deployment material lives next to the code:
PCR policy templates: policies/README.rst
SELinux policy: selinux/README.rst
EK root bundles: configs/ek-roots/README.rst
Example configuration: configs/lota.conf.example