Enroll a Compute Node (bare metal) - AMD SEV-SNP

Prev Next

1.0 Introduction

This article describes how to enroll a compute node on a bare-metal Advanced Micro Devices (AMD) Secure Encrypted Virtualization (SEV) - Secure Nested Paging (SNP) platform in Fortanix Confidential Computing Manager (CCM).

2.0 Enroll A Compute Node (bare Metal) – AMD SEV-SNP

2.1 Prerequisites

  • Ensure Simultaneous Multithreading (SMT) is disabled in BIOS when using AMD SEV-SNP. If enabled, the Confidential Virtual Machine (CVM) launch may fail with fw_error=7 'Policy is not allowed' error.

  • Ensure that you have completed all required CPU, GPU, and system configuration prerequisites as outlined in the NVIDIA Deployment Guide for Confidential Computing.

    • Check the Secure AI Compatibility Matrix to view the supported combinations of NVIDIA GPUs, VBIOS versions, CUDA driver versions, and Confidential Computing modes.

2.2 Ubuntu 26.04 Node Agent

Download the Ubuntu Node Agent installer from here.

Perform the following steps to enroll the Ubuntu 26.04 compute node:

  1. Run the following commands to extract the contents of the SNP-Node-Agent-installer.tar.gz package and open the folder:

    tar -zxvf SNP-Node-Agent-Installer.tar.gz
    cd em-agent-snp-installer
  2. Open the INSTALLER_README.md file containing the steps to enroll the compute node in Fortanix CCM.

    Text  Description automatically generated with medium confidence

    Figure 1: Readme.txt

  3. Run the following command to execute the installer.sh script:

    sudo bash installer.sh <join-token>

    Where, <join-token> is the token copied from Fortanix CCM. For more information, refer to Section 3.0: Generate a Join Token.

    NOTE

    For existing Fortanix CCM SaaS users, run the following commands to install the latest CCM node agent and update the ccm.fortanix.com endpoint to api.armor.fortanix.com:

    sudo apt update
    sudo apt upgrade em-agent

3.0 Generate a Join Token

Perform the following steps to generate a join token in Fortanix CCM:

  1. Log in to Fortanix Armor Platform. For more information, Access and Set Up Fortanix Armor.

  2. Navigate to the Fortanix CCM user interface (UI). For more information, refer to Fortanix Armor Solutions.

  3. In the CCM UI left navigation panel, click Infrastructure → COMPUTE NODES → AMD SEV-SNP, and then click ADD NODE.

    Figure 2: Add node

  4. In the Enroll Compute Node window, click COPY to copy the Join Token. This Join Token is used by the compute node to authenticate itself.

4.0 Validate the Enrolled Compute Node

After the compute node is successfully enrolled, it appears in the COMPUTE NODES overview table in Fortanix CCM.

Perform the following steps to debug the em-agent service:

  1. Run the following command to view the logs:

    journalctl -xe | grep em-agent
  2. Run the following command to view the status of the em-agent service or check the system logs directly:

    systemctl status em-agent

Fortanix-logo

4.6

star-ratings

As of August 2025