The first link in the chain: boot time verification.
A Nox CVM doesn't receive secrets automatically. It must prove it booted the expected OS image and application stack on attested TDX hardware first. Secrets earned, not handed over.
A Nox CVM doesn't receive secrets automatically. It must prove it booted the expected OS image and application stack on attested TDX hardware first. Secrets earned, not handed over.
