Due to the enclave architecture of the Google Cloud Confidential Space Co-signer, maintenance operations can only be performed through Google Cloud’s portal or using
gcloud.- View the logs
- Observe the status
- List the paired API users
- Retrieve the public key (used for the Callback Handler JWT authentication)
- Stop the Co-signer
- Restart the Co-signer
- Retrieve the running version
- Update the Co-signer
- Migrate to a new machine
- Configure a proxy server
- Configure the communication protocol
Check Co-signer status via API
To check whether a Co-signer is online or offline programmatically, call Get API key for an API key paired with the Co-signer. Infer the Co-signer’s status from thelastSeen timestamp in the response — a recent value indicates the Co-signer is online.
To find the cosignerId and paired apiKeyId, use Get all cosigners and Get all API keys.

AWS Nitro
AWS Nitro Co-signer maintenance

GCP Confidential Space
Google Cloud Confidential Space Co-signer maintenance

Intel SGX
SGX-based Co-signer maintenance on Azure, On-Premise, IBM Cloud, or Alibaba Cloud