> The host key section makes me wonder about doing this with servers, but what are the security guarantees in places like the cloud with that? Are you relegated to a software TPM, and if so, what guarantees does a software TPM have?
For the cloud? You would probably have a software TPM so not super secure, but you would still prevent the keys from being extracted away from the server. And if you don't trust your hypervisor/cloud provider you probably have other issues?
In my head the security guarantees are more straightforward for physical servers where you have a fTPM or a dTPM.
> My question after reading the README.md: what are the requirements from the OS? Can it be Windows, Linux, etc?
This only supports Linux.