This article provides an overview of new features and improvements in the Fortanix Confidential Computing Manager (CCM) 3.30 release.
1. Prerequisites
A container registry account to push the converted application container Image(s).
A subscription account on Azure Portal to create Compute Node/s.
2. New Features
CCM SaaS:
This release of CCM brings initial support for Azure Confidential Container Instances (ACI) using AMD-SEV SNP as an underlying hardware platform. This platform is still in the Public Preview phase with Azure; for more information see our announcement:
Support for Confidential Azure Container Instances | Fortanix
ACI announcement: Announcing public preview of confidential containers on Azure Container Instances
Refer to the following articles for instructions on how to use ACI with Fortanix CCM:
Added compute node agent support for Nitro instances on Amazon Web Services (AWS) Elastic Kubernetes Service (EKS).
For more details, refer to Amazon Elastic Kubernetes Service with Fortanix CCM
3. Improvements
Enclave OS:
Updated the libraries used for filesystem support feature in the conversion process.
Fixed the uncheck pointer overflows in
sgx_is_within_userfunction.
4. Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the max limit.
ACI and compute node agent for EKS features in 3.30 offer limited support. The following are limitations:
ACI does not support workflows.
Applications with network or port configuration are not supported on EKS.
To report an issue or bug, visit https://support.fortanix.com/hc/en-us/requests/new.
5. Node Agent Download
Download link for SGX Platform: Fortanix Node Agent Software - Intel SGX Platform
Download link for AWS Nitro Platform: Fortanix Node Agent Software - AWS Nitro Platform
NOTE
The current version of the node agent on Azure Marketplace will not create certificates.