Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracker: Confidential Virtualization Host with AMD SEV-SNP #1777

Open
marmijo opened this issue Aug 16, 2024 · 3 comments
Open

Tracker: Confidential Virtualization Host with AMD SEV-SNP #1777

marmijo opened this issue Aug 16, 2024 · 3 comments

Comments

@marmijo
Copy link
Member

marmijo commented Aug 16, 2024

Upstream Fedora Change: https://fedoraproject.org/wiki/Changes/ConfidentialVirtHostAMDSEVSNP

Fedora is introducing support for AMD SEV-SNP, which enables Fedora virtualization hosts to launch confidential virtual machines.

This is to track adding support for this change in FCOS and ensuring that the OS can function as a guest operating system in environments utilizing AMD SEV-SNP.

This was discussed during the community meeting on 2024-07-24 ([meeting log).

Guest owners will be able to prove that their OS is running in a Fedora host confidential virtual machine protected by AMD SEV-SNP, by performing a guest attestation

  • We'll investigate what changes are needed to perform this "guest attestation" in order to support AMD SEV-SNP.
  • If this doesn't work "out-of-the-box" and changes are needed, we'll add a test for it.
  • Will these changes extend to RHCOS as well?
@HuijingHei
Copy link
Member

cosa issue coreos/coreos-assembler#3556

@HuijingHei
Copy link
Member

HuijingHei commented Sep 4, 2024

Confirm that we already support AMD SEV-SNP type confidential instances on GCP (See coreos/coreos-assembler#3547), so what we should do is to add tests.

For Azure, need to confirm.
Edit: see #1777 (comment)

@travier
Copy link
Member

travier commented Nov 20, 2024

Note that this is about running FCOS as a SEV-SNP host and so far, most of our testing in clouds as been about running FCOS as a SEV-SNP Guest. It's not clear to me if we can nest SEV-SNP or if we can get access to hardware to test that in clouds.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants