COCONUT-SVSM (the COCONUT Secure VM Service Module) is a project under the Confidential Computing Consortium. It provides secure services and device emulation to guest operating systems in confidential virtual machines. It runs in the guest's trusted context, with current support focused on AMD SEV-SNP and Intel TDX. The main implementation lives in the SVSM repository.
- Documentation home — project overview and technical documentation.
- Installation guide — build the required host, firmware, QEMU, and SVSM components, then launch a guest.
- Developer information — contribution process and guidelines. The documentation site's Developer Information section also covers testing, debugging, and design topics.
- Development plan — design principles and planned or ongoing work.
| Repository | Purpose |
|---|---|
| svsm | Main COCONUT-SVSM implementation and documentation. |
| governance | Project governance, policies, groups, and meeting information. |
| coconut-alloc | Heap allocator used by COCONUT-SVSM. |
| cocoon-tpm | Rust workspace for a software TPM and related cryptography and storage components. |
| cpufeature | x86 CPUID feature checking library. |
| packit | Library and command-line tool for packing filesystems into single blobs. |
| kbs-test | Test server that mimics a Key Broker Service for SVSM attestation testing. |
| linux | Linux fork with host kernel support needed to run SVSM guests. |
| qemu | QEMU fork for SVSM and IGVM guest launch support. |
| virtio-drivers | Fork of the Rust VirtIO guest drivers. |
| edk2 | Archived EDK II firmware fork. |
| ms-tpm-20-ref | Archived TPM 2.0 reference implementation fork. |
| codeowner-tests | Test repository for CODEOWNERS behavior. |
For the current repository list, see the COCONUT-SVSM GitHub organization.