Confidential-attested nodes (SEV-SNP / TDX) where the host operator cannot read guest memory — with one Ed25519/WORM trust root end to end.