Loading...

Confidential VM node pool with AMD SEV-SNP protection available on AKS in public preview

Confidential VM node pool with AMD SEV-SNP protection available on AKS in public preview

Microsoft’s zero-trust policy aims at eliminating threats from malicious admins who have physical access to on-prem computing resources, as well as those within the cloud service provider. With the general availability of confidential virtual machines utilizing 3rd Gen AMD EPYC™ processors, organizations can deploy Azure virtual machines with higher level of protections from Hypervisor and Datacenter admins with encrypted memory and guest attestation capability rooted to the hardware. 

 

We’re excited to announce that Microsoft’s latest offering in its industry leading confidential computing portfolio focuses on transitioning on-prem Kubernetes managed infrastructure to the cloud. Azure Kubernetes Service (AKS) provides enterprise security capabilities for organizations to deploy containers at scale. AKS is the first to market in enabling confidential VM with AMD SEV-SNP node pools in Kubernetes, adding defense-in-depth to Azure's hardened security profile.  

 

Azure confidential VMs (DCav5/ECav5) are VM based Hardware Trusted Execution Environment (TEE) that leverage SEV-SNP security features to deny the hypervisor and other host management code access to VM memory and state, providing defense in depth protections against operator access. It enables easy migration of legacy workloads with no code changes and minimal performance impact. Having confidential VMs on AKS allows organizations to shift their highly sensitive, regulated resources from resource restrictive on-prem environments to Azure and benefit from the full feature support of AKS.  

 

Lift and Shift with full AKS feature support 

Confidential node pools on AKS enable a seamless lift-and-shift of Linux container workloads. Migrating to AKS means that organizations can now opt into a highly scalable, full AKS feature parity without the overhead of changing code or performance degradation. You can target sensitive workloads to confidential nodes using simple node pool affinity annotations through pod spec yaml/helm changes. 

 

Heterogenous Node Pools 

AKS is now equipped to have confidential and non-confidential node pools in a single cluster. This means apps processing sensitive data can reside in a VM-level TEE node pool with memory encryption keys generated from the chipset itself. The DCasv5 and ECasv5 confidential VMs will also support remote guest attestation allowing AKS admins to target pod deployments to only attested nodes in the near future. The below picture shows AKS node's code and data under the AMD SEV-SNP memory protection. 

 

 

AnanyaGarg_0-1659379696029.png

 

 

 Get Started 

You can add confidential VM node pools to an existing AKS cluster using the az aks nodepool add command. Specify the name cvmnodepool, and use the --node-vm-size parameter to specify the Standard_DC2as_v5 size: 

 

az aks nodepool add \ --resource-group myResourceGroup \ --cluster-name myAKSCluster \ --name cvmnodepool \ --node-count 3 \ --node-vm-size Standard_DC2as_v5 \

 

This confidential VM size is a part of our  generally available DCasv5 and ECasv5 confidential VM-series, click to learn more.

 

 

 

Published on:

Learn more
Azure Confidential Computing Blog articles
Azure Confidential Computing Blog articles

Azure Confidential Computing Blog articles

Share post:

Related posts

Adams Bridge: An Accelerator for Post-Quantum Resilient

The name Adams Bridge is inspired by the mythological structure which was said to span a vast gulf between two landmasses. In the realm of cry...

1 year ago

General Availability: Azure confidential VMs with NVIDIA H100 Tensor Core GPUs

Today, we are announcing the general availability of Azure confidential virtual machines (VMs) with NVIDIA H100 Tensor core GPUs. These VMs co...

1 year ago

Azure AI Confidential Inferencing: Technical Deep-Dive

Generative AI powered by Large Language Models (LLMs) has revolutionized the way we interact with technology. Through chatbots, co-pilots, and...

1 year ago

Verify the integrity of Azure Confidential Ledger transactions with receipts and application claims

In today's digital landscape, the integrity and confidentiality of transactional data are paramount. Microsoft’s Azure Confidential Ledger off...

2 years ago

Memory Protection for AI ML Model Inferencing

This article was originally posted on Confidential Container Project's blog by Suraj Deshmukh & Pradipta Banerjee. Read the original artic...

2 years ago

General Availability: Azure Managed HSM Backup/Restore when Storage is Behind a Private Endpoint

We are excited to announce the General Availability of support for Azure Key Vault Managed HSM backup/restore when the sto...

2 years ago

Public Preview: Azure Managed HSM Backup/Restore when Storage Account is Behind a Private Endpoint

We are excited to announce the Public Preview of support for Azure Key Vault Managed HSM backup/restore when the storage accoun...

2 years ago

General Availability: Managed HSM Networking Settings in Azure Portal

We are excited to announce the General Availability of networking settings for Azure Key Vault Managed HSM on the Azure po...

2 years ago

New innovations in confidential computing from Azure at Ignite 2023

Azure has been a pioneer and leader in the field of confidential computing, offering the most comprehensive portfolio of products and services...

2 years ago

Announcing Azure confidential VMs with NVIDIA H100 Tensor Core GPUs in Preview

Today, we are excited to announce the preview of Azure confidential VMs with NVIDIA H100 Tensor core GPUs.  These VMs are ideal for ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.