{
  "accepted_hostdata": [
    "af8fd9c83877d69d4209446db7f9fc5b3d660d437a75910bcdfc6a3f835c2dd4",
    "1f055326400b1e45697e4576aa4a4f4ea8a819c6cddfea98d0bbba0c45925449"
  ],
  "api_base_url": "https://api-azure.trustedrouter.com/v1",
  "attestation_format": "microsoft-azure-attestation-jwt",
  "attestation_issuers": [
    "https://trquilluaen.uaen.attest.azure.net",
    "https://trquillsyd.eau.attest.azure.net"
  ],
  "attestation_type": "sevsnpvm",
  "data_policy": {
    "client_telemetry_content_free": true,
    "client_telemetry_disclosure": "https://trustedrouter.com/docs/telemetry",
    "control_plane_prompt_access": false,
    "prompt_output_storage": false
  },
  "evidence_note": "MAA re-attests the SEV-SNP report; verifiers see Microsoft's assertion, not the raw hardware report or the AMD certificate chain.",
  "hostdata": "af8fd9c83877d69d4209446db7f9fc5b3d660d437a75910bcdfc6a3f835c2dd4",
  "measurement_type": "sev-snp-hostdata-sha256",
  "platform": "azure-confidential-containers-sev-snp",
  "regions": [
    {
      "attestation_issuer": "https://trquilluaen.uaen.attest.azure.net",
      "attestation_url": "https://api-azure.trustedrouter.com/attestation",
      "compliance_status": "azure-compliant-uvm",
      "hostdata": "af8fd9c83877d69d4209446db7f9fc5b3d660d437a75910bcdfc6a3f835c2dd4",
      "launch_measurement": "dc3f5a934489232a9b1818f12a0a88d2324ced00f8ab370f40451a76b7880bc3e211849a0739642d3d6c3b2b4bfb9866",
      "origin_hostname": "quill-enclave-uaenorth.uaenorth.azurecontainer.io"
    },
    {
      "attestation_issuer": "https://trquillsyd.eau.attest.azure.net",
      "attestation_url": "https://api-azure-syd.trustedrouter.com/attestation",
      "compliance_status": "azure-compliant-uvm",
      "hostdata": "1f055326400b1e45697e4576aa4a4f4ea8a819c6cddfea98d0bbba0c45925449",
      "launch_measurement": "dc3f5a934489232a9b1818f12a0a88d2324ced00f8ab370f40451a76b7880bc3e211849a0739642d3d6c3b2b4bfb9866",
      "origin_hostname": "quill-enclave-australiaeast.australiaeast.azurecontainer.io"
    }
  ],
  "release_state": "multi-region",
  "source_commit": "00573cf9e6445c5cf1a078a88a3b053e8360547d",
  "source_commit_provenance": "operator-asserted",
  "source_repo": "https://github.com/Lore-Hex/quill-cloud-proxy",
  "tls": {
    "hostname": "api-azure.trustedrouter.com",
    "mode": "acme-inside-confidential-container"
  },
  "transparency": {
    "bundle": "azure-release.json.bundle",
    "certificate_identity": "https://github.com/Lore-Hex/quill-cloud-proxy/.github/workflows/publish-trust-azure.yml@refs/heads/main",
    "certificate_oidc_issuer": "https://token.actions.githubusercontent.com",
    "newest_check": "The signature proves who wrote this record and when, not that it is the newest one. Search the transparency log for the identity above; the log is append-only, so a newer entry cannot be hidden from you. The bundle carries a Signed Entry Timestamp but no inclusion proof, so confirming log membership requires querying Rekor.",
    "running_check": "Neither the signature nor the log says this measurement is still what is RUNNING \u2014 an unchanged deployment should carry an old signature, so age is not drift. Fetch a live attestation from api_base_url and compare it against the accepted set in this record.",
    "transparency_log": "https://rekor.sigstore.dev",
    "verify": "cosign verify-blob --bundle azure-release.json.bundle --certificate-identity https://github.com/Lore-Hex/quill-cloud-proxy/.github/workflows/publish-trust-azure.yml@refs/heads/main --certificate-oidc-issuer https://token.actions.githubusercontent.com azure-release.json"
  }
}
