Loading...

Microsoft introduces preview of confidential containers on Azure Container Instances (ACI)

Microsoft introduces preview of confidential containers on Azure Container Instances (ACI)

Microsoft has announced a limited preview of confidential containers support on Azure Container Instances (ACI). Confidential containers on ACI provides a fully managed serverless offering allowing customers to easily lift-and-shift Linux containers on Azure. Confidential containers on ACI are the first in the market serverless offering that helps running Linux containers in a hardware-based trusted execution environment with AMD SEV-SNP technology. With confidential containers on ACI, customers can easily run existing containerized workloads in a verifiable hardware-based Trusted Execution Environment (TEE).  To get access in the upcoming limited preview, please sign up at aka.ms/ccacipreview.

 

Azure confidential computing (ACC) protects data in use by processing it only within a protected area of the CPU, which helps protect data from cloud operators, malicious admins, and privileged software. This data in use protection adds further defense in depth on top of existing solutions in Azure for protecting data on the network and in storage. Meanwhile, customers are continuously looking for reduced overhead on infrastructure management and ACI is a popular choice for customers wanting to run containers quickly and simply on Azure without deploying and managing Virtual Machines (VMs). Confidential containers on ACI enable customers to achieve hardware-based data in use encryption and verifiable assurance through guest attestation while leveraging the benefits of a fully managed serverless containers platform.

 

Hardware based Trusted Execution Environment (TEE) and Isolation

Confidential containers on ACI supports applications built on Linux based images and provide hardware-based isolation per container group. Confidential containers on ACI are deployed in a container group with a Hyper-V isolated TEE including a memory encryption key that is generated and managed by an AMD EPYC SEV-SNP capable processor. Customers can deploy a set of containers in a single container group within the same TEE that encrypts the data while in use in memory and helps guard against attacks from other container groups or malicious OS, Hypervisor components. The TEE also provides memory integrity protection guarding against attacks like replay and memory remapping. Hyper-V based isolation deployment mechanisms with a dedicated SEV-SNP enlightened Linux kernel per container group to further protect your deployments

 

Remote Guest Attestation

 

AC-Attestationflow.jpg Attestation allows the relying party to verify that the service is running in a TEE before sensitive data for processing. Confidential containers allow services in the container group to fetch the AMD SEV-SNP hardware report and use it as part of the attestation flow. This capability can be extended to your workloads to verify that your apps are running in a TEE before a data decryption key is exchanged or client to server contract is established.

 

Deployment Experience

During preview ARM templates can be used for your deployments. Confidential containers are deployed by modifying a few lines in the typical ACI deployments. Below is a simple demo on how customers can run a Python application that can read a TEE attestation report and show it as a web page. 

 

Conf-container-create.gif

 

We are excited to bring confidential serverless offerings with full lift & shift container support while continuing to innovate in this fast-emerging confidential computing and cloud native space. Join our preview list by signing up at aka.ms/ccacipreview 

 

Helpful Links

Published on:

Learn more
Azure Confidential Computing Blog articles
Azure Confidential Computing Blog articles

Azure Confidential Computing Blog articles

Share post:

Related posts

Adams Bridge: An Accelerator for Post-Quantum Resilient

The name Adams Bridge is inspired by the mythological structure which was said to span a vast gulf between two landmasses. In the realm of cry...

1 year ago

General Availability: Azure confidential VMs with NVIDIA H100 Tensor Core GPUs

Today, we are announcing the general availability of Azure confidential virtual machines (VMs) with NVIDIA H100 Tensor core GPUs. These VMs co...

1 year ago

Azure AI Confidential Inferencing: Technical Deep-Dive

Generative AI powered by Large Language Models (LLMs) has revolutionized the way we interact with technology. Through chatbots, co-pilots, and...

1 year ago

Verify the integrity of Azure Confidential Ledger transactions with receipts and application claims

In today's digital landscape, the integrity and confidentiality of transactional data are paramount. Microsoft’s Azure Confidential Ledger off...

2 years ago

Memory Protection for AI ML Model Inferencing

This article was originally posted on Confidential Container Project's blog by Suraj Deshmukh & Pradipta Banerjee. Read the original artic...

2 years ago

General Availability: Azure Managed HSM Backup/Restore when Storage is Behind a Private Endpoint

We are excited to announce the General Availability of support for Azure Key Vault Managed HSM backup/restore when the sto...

2 years ago

Public Preview: Azure Managed HSM Backup/Restore when Storage Account is Behind a Private Endpoint

We are excited to announce the Public Preview of support for Azure Key Vault Managed HSM backup/restore when the storage accoun...

2 years ago

General Availability: Managed HSM Networking Settings in Azure Portal

We are excited to announce the General Availability of networking settings for Azure Key Vault Managed HSM on the Azure po...

2 years ago

New innovations in confidential computing from Azure at Ignite 2023

Azure has been a pioneer and leader in the field of confidential computing, offering the most comprehensive portfolio of products and services...

2 years ago

Announcing Azure confidential VMs with NVIDIA H100 Tensor Core GPUs in Preview

Today, we are excited to announce the preview of Azure confidential VMs with NVIDIA H100 Tensor core GPUs.  These VMs are ideal for ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.