Skip to main content

syft-enclave

Enclave support for syft, enabling secure computation in Trusted Execution Environments (TEEs).

About

Prerequisites

  • Docker with buildx support (Docker Desktop includes this)
  • gcloud CLI installed
  • A GCP project with billing enabled
  • just and jq

All commands are defined in the Justfile. Run them from this directory.

Prefer declarative deploys? The same stack can be managed with Terraform — see Terraform Deployment (just tf-apply / just tf-apply-dev).

One-time setup

just init YOUR_GCLOUD_PROJECT_ID TOKEN_PATH DATA_OWNERS
  • TOKEN_PATH — credentials of the enclave email downloaded from the gcloud console.
  • DATA_OWNERS — comma-separated emails of the data owners whose approval gates every job on this enclave, e.g. do1@openmined.org,do2@openmined.org.

This stores settings (including data_owners) in ~/.syft-enclaves/settings.json and sets the active gcloud project. Every other recipe reads project_id, zone, and data_owners from this file — zone is not a per-call arg. To deploy in a different zone or change the data owners, re-run just init YOUR_PROJECT_ID TOKEN_PATH DATA_OWNERS europe-west4-a.

Approval model

The data owners configured at init are fixed for the enclave: a job runs only after all of them approve it, regardless of which datasets the submission references. The emails are passed to the VM as SYFT_ENCLAVE_DATA_OWNERS at deploy time and held in memory by the running enclave. To change the approving data owners, re-run just init and redeploy.

Production deployment

Hardened image — no SSH access, TEE enforcement enabled.

just start EMAIL                          # defaults: syft-enclave-vm, n2d-standard-2
just start EMAIL my-vm n2d-standard-4     # override name / machine type
just stop [name]                          # Teardown: Deletes the VM (default: syft-enclave-vm)

The first run also provisions APIs and IAM roles (idempotent). No inbound port is opened on the enclave — attestation is published through the peer flow, and all other traffic is outbound.

Debug deployment

Debug image — SSH enabled, container logs redirected to serial output.

just start-debug EMAIL                          # defaults: syft-enclave-vm, n2d-standard-2
just start-debug EMAIL my-vm n2d-standard-4     # override name / machine type
just stop [name]                                # Teardown: Deletes the VM.

Debug enclaves run with encryption off — data owner clients must match: login_do(encryption=False).

GPU deployments

Prefix any deploy with hardware=gpu to switch from the CPU default to a3-highgpu-1g (1× H100 80GB, Intel TDX):

just hardware=gpu start EMAIL           # production
just hardware=gpu start-debug EMAIL     # debug

GPU enclaves use flex-start provisioning: the create call may wait for H100 capacity (up to 2h), then the VM runs gpu_run_duration_seconds (default 2 days). Details: docs/terraform.md — GPU deployments.

Inspect a running VM

All inspect commands take an optional name (default: syft-enclave-vm). Zone is always read from settings.json.

# Works on both production and debug
just status [name]   # RUNNING / TERMINATED / etc.
just get-ip [name]   # external IP

# Debug only
just attest [name]   # fetch TEE attestation report via SSH (no inbound port is open;
                     # production publishes attestation through the peer flow instead)
just ssh    [name]   # SSH into the VM (production image disables SSH)
just logs   [name]   # last 50 lines of serial output (production only shows boot logs;
                     # debug redirects container logs to serial output)

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

syft_enclave-0.1.0-py3-none-any.whl (26.6 kB view details)

Uploaded Python 3

File details

Details for the file syft_enclave-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: syft_enclave-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 26.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.8

File hashes

Hashes for syft_enclave-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ebef066f39916535fb05798a0981b93da5d279c5b18437a639c073bab04e0ade
MD5 273995785f1c0cf41a209b8d26f30cd2
BLAKE2b-256 c6018b5e0b81d5af084b1f9edce567e50fc0ad4223484e94e7bb6077ce40e335

See more details on using hashes here.

Release history Release notifications | RSS feed

0.1.1

2 files

This release

0.1.0 This release

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page