Skip to content

docs: correct Cobalt TEE feature summary to registration migration - #2014

Merged
roethke merged 5 commits into
masterfrom
roethke/cobalt-tee-registration-summary
Sep 25, 2026
Merged

roethke merged 5 commits into
masterfrom
roethke/cobalt-tee-registration-summary

Conversation

@roethke

@roethke roethke commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

What changed? Why?

The TEE Migration accordion on the Cobalt overview says Cobalt "migrates Base infrastructure to run inside a Trusted Execution Environment (TEE)" and that specs are pending. That describes the wrong feature. The actual work, specified in #1953, keeps the existing TEE setup and changes only how new TEE signers are registered: the registrar verifies AWS Nitro attestations onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow.

This PR:

Notes to reviewers

Two things worth a look:

  • Anchor change. The retitle moves the deep link from #tee-migration to #tee-registration-migration. Mintlify does not redirect heading anchors, so any external link to the old anchor lands on the page top. Happy to keep the original title if that matters more than matching docs: add Upcoming Features page for planned protocol work #1953's naming.
  • Index files edited by hand. Running node scripts/llms.js regenerated unrelated drift against master (Tokenized Stocks entries, and a specifications/b20 → specifications/b20/index URL change). I reverted that and applied only the one Cobalt description line to each file to keep the diff scoped. The generator drift looks worth a separate fix.

How has it been tested?

  • node scripts/validate-docs-structure.js passes
  • node scripts/check-terminology.js passes
  • node scripts/lint-mdx.js docs/upgrades/cobalt/overview.mdx: 0 errors, 0 warnings

Screenshots

Pending. Text-only change to one accordion body; the Mintlify preview renders it.

The Cobalt overview described the TEE feature as migrating Base
infrastructure to run inside a TEE. The actual work, specified in #1953,
replaces the RISC Zero and Boundless proving flow for registering new TEE
signers with onchain AWS Nitro attestation verification using checked
P-384 hints.

Retitles the accordion to "TEE Registration Migration", rewrites the
summary to match, links the Registrar specification, and updates the page
description plus its llms.txt / llms-full.txt index lines.

Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>
@mintlify

mintlify Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
base 🟢 Ready View Preview Sep 25, 2026, 7:01 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@cb-heimdall

cb-heimdall commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Heimdall Review Status

Requirement Status More Info
Reviews ✅ 1/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 0
Sum 1

roethke and others added 2 commits September 25, 2026 11:26
Per review: emphasize that verification is now trustless and fully
onchain, clarify that the removed proving dependency was offchain, and
drop the certificate-caching transaction counts as too nuanced for a
high-level summary.

Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>
…summary' into roethke/cobalt-tee-registration-summary
@roethke

roethke commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator Author

Thanks @leopoldjoy, all three applied in a82e058:

  1. Trustlessly and fully onchain — added, exactly as suggested.
  2. Certificate caching — dropped. Agreed it's misleading at a high level given the count depends on cache recency.

Updated summary:

Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: the registrar verifies AWS Nitro attestations trustlessly and fully onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external offchain proving service. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See Registrar for the full specification.

Also merged master in, since the branch had picked up a merge commit on GitHub. Structure, terminology, and MDX lint checks still pass.

The registrar is the offchain component; verification happens in the
onchain contracts. Recast the clause in the passive to avoid implying the
registrar performs the verification.
@roethke
roethke merged commit 5d18728 into master Sep 25, 2026
15 checks passed
@roethke
roethke deleted the roethke/cobalt-tee-registration-summary branch September 25, 2026 19:03

This branch was successfully deployed

1 active deployment
staging - docs — 1cbc87b7 Deployed Sep 25, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants