Hello,
I have been trying to better understand confidential VMs. A big part of having a trusted domain is attesting it and verifying the hardware and software you are running.
Up until now, with the help of go-tpm-tools, I have been able to get a quote, for the hardware/ bootloader, and using the same tool kind of got a verification that the quote was good.
What I can not seem to do is get a quote for the software or programs running on the machine.