Skip to main content
The quickstart deploys a pre-built Docker image. If you have another pre-built image, reference it directly in the image field of your tinfoil-config.yml. For your own source code, use the Dockerfile and Build Image workflow in tinfoil-containers-hello-world as a starting point:
  • Public source: keep the application, image-build workflow, config, and measured-release workflows in one public repository.
  • Private source: keep the application and image-build workflow in a private repository. Reference the published image from a public tinfoil-containers-template repository.
If the published image is private (not just the source), Tinfoil needs registry credentials to pull it at deploy time. See Private images. Public images work without any configuration.

Build and publish

  1. Edit your application and Dockerfile.
  2. Run Build Image (build-image.yml) with an image version. It pushes the image to GHCR and prints the digest in the workflow summary.
  3. Copy that digest into tinfoil-config.yml and commit the config to the default branch.
  4. Run Tinfoil Release with a new release version. Wait for both the tag-creation and measurement/publication phases to succeed before creating or updating an instance.
Building an image does not publish a deployable enclave release or update a running instance.

Image digests in the release workflow

The image field must pin the exact image with its SHA256 digest:
tinfoil-config.yml
Replace <digest> with the real digest from your build or registry before publishing. The measured-release workflow uses the committed config; it does not build the image or fill in a placeholder digest.