Ensure that your Kubernetes cluster and nodes meet the following requirements before deploying Fortanix Armor.
Kubernetes Cluster Requirements
Ensure that a Kubernetes cluster (for example, Azure Kubernetes Service (AKS)) is provisioned and accessible.
A Kubernetes cluster should be configured with separate node pools:
System node pool: Used for core Kubernetes components and general workloads. This pool can use non-SGX VM instances and should have a minimum of three nodes for high availability. The minimum supported VM size is Standard_D4d_v5.
User node pool (SGX-enabled): Used for running Fortanix Armor workloads that require SGX. This pool must use SGX-capable VM instances. The minimum supported VM size is Standard_DC8s_v3 (DC8s_v3), or a later supported SGX-enabled VM size. SGX must be enabled according to the cloud provider configuration (for example, by enabling the SGX add-on in AKS).
The node pools should be running Linux. Fortanix has validated this deployment on Ubuntu 24.x version.
Kubernetes version: 1.35.8 or later (or supported non-end-of-life version).
INITIAL AKS VERSION
SUPPORTED UPGRADE VERSIONS
1.35.8
1.36.0
1.36.0
1.36.x (minor updates)
The cluster must have a minimum of three nodes for user pool.
Ensure that the
KUBECONFIGenvironment variable is set in the environment used to run Helm commands for installing the Fortanix Armor Kubernetes Operator.For example,
export KUBECONFIG=<path-to-kubeconfig>Where,
<path-to-kubeconfig>is the file path to your Kubernetes configuration file. For example:$HOME/.kube/config.
Node Requirements
Configure SGX Support on the Kubernetes cluster:
The Kubernetes cluster must include node pools with SGX-capable VM instances to run Fortanix Armor workloads.
Intel SGX must be enabled and functional on these nodes.
The Intel SGX Device Plugin must be installed in the cluster and expose the following resources:
sgx.intel.com/enclavesgx.intel.com/provision
NOTE
For Azure AKS, SGX support requires enabling the SGX add-on when creating the cluster. For detailed steps, refer to Microsoft official documentation.

Figure 1: SGX plugin running
Configure User Node Pool (SGX-Enabled) Labelling in AKS
Fortanix Armor SGX workloads, such as node-agent and sgx-quote-helper should run only on SGX-enabled nodes.
In AKS clusters with multiple workload types, Kubernetes might schedule these workloads on nodes that do not support SGX if SGX-specific scheduling constraints are not configured.
To ensure correct scheduling behavior, install and configure Kubernetes Node Feature Discovery (NFD) in the cluster.
Example: NFD can be installed using Helm. The following commands are provided as an example:
helm repo add nfd <NFD-repository>
helm install nfd nfd/node-feature-discovery \
--namespace node-feature-discovery \
--create-namespaceNOTE
Fortanix does not provide or install NFD. The commands above are an example of how NFD can be installed. Use the installation method and repository appropriate for your Kubernetes environment.
The
node-feature-discoveryversion must be 0.15.0 or later.
After installing NFD, verify that SGX-enabled nodes have the following label:
feature.node.kubernetes.io/cpu-security.sgx.enabled=trueDeployment Topology
Deploy a Kubernetes cluster with the following node configuration:
Three control plane nodes for Kubernetes cluster management and Fortanix Armor platform components.
One pre-provisioned cold standby worker node for disaster recovery (recommended).
Medusa Storage account on Azure for backup and restore with outbound internet connection.
Server Specifications
Each server should meet or exceed the following specifications:
COMPONENT | MINIMUM REQUIREMENT |
|---|---|
Server Platform | Dell PowerEdge R470 Chassis |
Processor | Intel Xeon 6521P (24 cores) |
Memory | 128 GB RAM or higher |
Storage | 1 TB or larger NVMe SSD |
Network | Dual 10 GbE network ports |
Power | Dual redundant power supplies |
Kubernetes Cluster Requirements
Ensure that a Kubernetes cluster is provisioned and accessible.
Kubernetes version: 1.35.x or later.
Kubernetes control plane components run on the control plane node, while Fortanix Armor platform components are deployed on the worker nodes.
Ensure that the control plane and worker nodes are in the Ready state.
Run the following command:
kubectl get nodesExpected output:
NAME STATUS ROLES VERSION Control-plane-1 Ready control-plane v1.35.1 worker-1 Ready <none> v1.35.x worker-2 Ready <none> v1.35.x worker-3 Ready <none> v1.35.x
Node Requirements
Ensure that the Kubernetes cluster worker nodes with Ubuntu/Debian OS are SGX-capable and have Intel SGX enabled.
Verify that the SGX device files are available on each worker node by running the following command:
ls -l /dev/sgx*Expected output:
/dev/sgx_enclave /dev/sgx_provisionIf these device files are not present, verify that Intel SGX is enabled in the system BIOS and that the Intel SGX software stack is installed.
Install and Configure the Intel SGX Device Plugin and Node Feature Discovery (NFD).
For instructions to deploy NFD and the Intel SGX Device Plugin, refer to the Intel SGX Device Plugin documentation.
Run the following command to verify that the Intel SGX Device Plugin is running in the Kubernetes cluster:
kubectl get pods -n inteldeviceplugins-system -owideThe output should include the Intel SGX Device Plugin pods in the Running state.
.png?sv=2026-02-06&spr=https&st=2026-10-09T06%3A18%3A55Z&se=2026-10-09T06%3A32%3A55Z&sr=c&sp=r&sig=VdUI9LjH4U4m9lBPmkZxH5LYPfCN87J%2BPVtgcSJwuBc%3D)
Figure 1: SGX Plugin Running
Run the following command to verify that the Intel SGX resources are exposed on each worker node:
kubectl describe node <nodename>In the Allocatable section, verify that the following resources are present:
sgx.intel.com/enclavesgx.intel.com/provision
Additional Kubernetes Requirements
Kubernetes cluster must not have K8ssandra installed.
Kubernetes cluster must have an Ingress Controller installed. An example Ingress Controller is described in Configure Ingress Controller.
cert-manager must be installed and configured in the Kubernetes cluster. For steps to install cert-manager, refer to Install Cert Manager.
You must have Helm installed and access configured to deploy resources to the cluster.
Certificates - External or Internal Certificate Authority (CA) to sign Fortanix Armor UI and API certificates.
Customer-managed Cassandra deployments are not supported.