VoltageGPU evidence bundle: single-GPU RTX PRO 6000 Blackwell Server Edition, Intel TDX guest Captured 2026-09-17 00:00 UTC from inside a VoltageGPU Confidential VM (SKU rtx6000b-small). What this shows Both proofs, generated by the tenant inside the VM, on a challenge the tenant chose: 1. An Intel TDX quote (v4, TEE 0x81, 4 940 bytes) whose report_data is the SHA-512 of the manifest, verified offline up to the pinned Intel SGX Root CA, with Intel PCS collateral (TCB info, QE identity, CRLs) embedded. Platform TCB UpToDate. 2. NVIDIA GPU attestation tokens from NRAS whose eat_nonce is the SHA-256 of the same manifest: measurements ok, secure boot on, debug off, report signature and chain validated. GPU-0 GB20X, driver 595.71.05, vbios 98.02.9E.00.01. Environment read inside the guest (conf-compute.txt, gpu.txt, kernel.txt) systemd-detect-virt: kvm, /dev/tdx_guest present, kernel 6.8.0-110-generic nvidia-smi conf-compute -q: CC State ON, Multi-GPU Mode None, CPU CC INTEL TDX, GPU CC Capable, CC GPUs Ready State Ready Protected memory 99 463 296 KiB, unprotected 0 KiB Why it matters Until this capture our product page said "Intel TDX quote only, GPU attestation not verified on this SKU" and our older notes said the RTX 6000B read CC OFF. That was stale. This is the third single-GPU SKU with both proofs, after H200 (2026-09-04) and H100 (2026-09-16), and the cheapest of the three. Files manifest.json the workload manifest with the random challenge (voltage-verify manifest --challenge auto) bundle.json the evidence bundle (voltage-verify attest --mode single-gpu, run as root in the VM) verify.txt full output of voltage-verify verify bundle.json, RESULT: VERIFIED conf-compute.txt nvidia-smi conf-compute -q and -gm gpu.txt nvidia-smi name, driver, vbios, memory kernel.txt uname -r, /dev/tdx_guest, systemd-detect-virt SHA256SUMS checksums computed inside the VM before download Reproduce (as it actually runs on the VM image, which ships without pip) curl -sS https://bootstrap.pypa.io/get-pip.py | python3 - --user --break-system-packages python3 -m pip install --user --break-system-packages "voltage-verify[attest]" export PATH=$HOME/.local/bin:$PATH voltage-verify manifest --challenge auto -o manifest.json sudo env PATH=$PATH PYTHONPATH=$(python3 -c 'import site;print(site.getusersitepackages())') \ voltage-verify attest --manifest manifest.json --mode single-gpu -o bundle.json voltage-verify verify bundle.json --challenge Then copy bundle.json off the VM and run the same verify on your own machine (pip install voltage-verify, https://github.com/Jabsama/voltage-verify, MIT), with --offline if you want no network at all. The NRAS tokens are signed by NVIDIA and the TDX quote by Intel's chain; a wrong --challenge makes verify answer NOT VERIFIED. A second bundle, produced the same day through the public API alone (deploy by API key, SSH, attest, stop), is in ../rtx6000b-api-2026-09-17/. Limits, stated plainly This is one GPU. On 8-GPU nodes NVIDIA runs Protected PCIe mode and the NVSwitch fabric is not attestable from inside a TDX guest (see ../nvswitch-2026-09-16/). NVIDIA's CLI verifier fails from inside the guest because OCSP is unreachable; the Python SDK in remote mode works because those checks run on NVIDIA's side. Checksums (sha256, computed in the VM) d793286612494ec22dca3f0d98607efc1b04ec86103d7c57a181f2889171ef41 bundle.json e6e145dcaae1dca0e50787aef77e08ff1887d9a0cac041adc9110f826f5a28dc manifest.json 300fdc87eb1dcdb5b46e5b18443339732a5bc3d26baa6aba88af3343652ec0bb verify.txt a29635e51e19c2391b0b55f1b8bbd9713df9354f1075a7547d85f2f4dcf0543f conf-compute.txt bf8c6451fe67ebdf7431c470b5ecc2f6367f7eb9e03e3251bfed59f33aa4bf5e gpu.txt 55b60a64b1b30af39dff7731e9f3be63595e13a293791d17f5514d4392c356d1 kernel.txt