This article provides an overview of improvements and known issues in the Fortanix Confidential Computing Manager (CCM) 3.33 release.
1. Prerequisites
A container registry account to push the converted application container Image(s).
A subscription account on Azure Portal to create Compute Node/s.
2. Improvements
CCM SaaS:
The
getBuildDeploymentsnow correctly returns deployments of the selected build.
Enclave OS:
The
PATHenvironment variable is now appropriately set in the client environment.An empty directory can be now mounted to
/opt/fortanix/enclave-os/overlayfs/directory of the Nitro converted image, where the persistent filesystem block file is saved.Detailed error message is displayed when the application runs out of memory.
Limited support is added for
sched_getschedulerandsched_getparamsystem call.Added support for
glibclibrary version 2.37. The update is backward compatible.
3. Known Issues
CCM SaaS:
Improved the functionality of Test Only accounts with Nitro and ACI platforms.
EnclaveOS:
Added a check for Nitro converter to verify if the key or certificate folder path is present in the client image.
The
/tmpdirectory can now be executed in Nitro Enclave if the client filesystem anticipates it.
4. Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the max limit.
ACI and compute node agent for EKS features in 3.30 offer limited support. The following are limitations:
ACI does not support workflows.
Applications with network or port configuration are not supported on EKS.
To report an issue or bug, visit https://support.fortanix.com/hc/en-us/requests/new.
5. Node Agent Download
Download link for SGX Platform: Fortanix Node Agent Software - Intel SGX Platform
Download link for AWS Nitro Platform: Fortanix Node Agent Software - AWS Nitro Platform
NOTE
The current version of the node agent on Azure Marketplace will not create certificates.