Create Application Configuration

Prev Next

1.0 Introduction

This article describes how to create an Application Configuration in Fortanix Confidential Computing Manager (CCM) to customize application behavior.

An Application Configuration is an object used to define application-specific settings for the following application types and platforms:

  • For Confidential Container - Enclave OS applications: Use this configuration to insert files at a specific path on the disk.

  • For EDP applications: Use this configuration to provide key-value pairs to the application.

  • For Azure applications: Use this configuration to provide key-value pairs that define runtime parameters for the application.

  • For Azure Confidential VM applications: Use this configuration to provide key-value pairs required to configure the application.

  • For Confidential VM applications: Use this configuration to provide key-value pairs that define runtime parameters for the application.

  • For Confidential Container - CoCo applications: Use this configuration to provide key-value pairs required to configure the application.

The Application Configuration also includes information about connections to datasets or other applications when the application is part of a workflow.

For example, you can use a Nginx Enclave OS build and provide a custom nginx.conf file using an application configuration.

2.0 Application Configuration Workflow

Application Configuration objects can be assigned to applications in draft workflows. These workflows are submitted for approval and finalized once all required users approve them.

After approval, Fortanix CCM generates a derived object called the Workflow Application Configuration. This object contains the original Application Configuration and workflow connection details required by enclaves to access datasets and other resources.

For more information about Fortanix CCM workflows, refer to Create, Update, Clone, and Delete Workflows.

3.0 Create an Application Configuration

Before creating an Application Configuration, ensure that the following objects already exist:

  • A Fortanix Armor Identity and Access Management (IAM) group

  • An application

  • An application build

Perform the following steps to create an Application Configuration:

  1. In the CCM user interface (UI) left navigation panel, navigate to Applications → CONFIGURATION, and click ADD CONFIGURATION to add a new configuration.

    Figure 1: Add Configuration

  2. In the Add Configuration form:

    1. Configuration name: Enter a name for the configuration.

    2. Description: Enter a description for the configuration.

    3. Group: Select the required group name from the drop down menu.

    4. Build: Select the application build for which the configuration will be created.

    5. Ports: Specify the connections used in the workflow. These are not network ports. They are string-based tags used to identify workflow connections. You can define multiple ports based on the connection requirements. For example, input, output, heartbeat, and so on.

    6. Label Details (optional): Add one or more key-value labels to the configuration.

    7. Configuration items: Click ADD CONFIGURATION ITEM and define key-value pairs used to configure the application.

      • For Confidential Container - Enclave OS applications, the Key represents the file path, and the Value represents the file content used to configure the application.

        NOTE

        For Enclave OS applications, files are allowed only under the opt/fortanix/enclave-os/app-config/rw path.

      • For EDP applications, specify the Key and Value required to configure the application.

      • For Azure ACI applications, specify the Key and Value required to configure the application.

      • For Azure Confidential VM applications, specify the Key and Value required to configure the application.

      • For Confidential VM applications on AMD SEV-SNP, specify the Key and Value required to configure the application. Leave the Ports value empty.

      • For Confidential VM applications on Intel TDX, specify the Key and Value required to configure the application.

      • For Confidential Container - CoCo applications on AMD SEV-SNP, specify the Key and Value required to configure the application.

      • For Confidential Container - CoCo applications on Intel TDX, specify the Key and Value required to configure the application.

  3. Click ADD CONFIGURATION to create the configuration.

    Figure 2: Application configuration added

Fortanix-logo

4.6

star-ratings

As of August 2025