Virtual HSM
Home
  • Virtual HSM
  • Documentation
    • What is Virtual HSM?
    • Use Case: Attested Secret Provisioning in the Cloud
    • Setup
      • Install
      • vHSM Server Configuration
        • Parameters
        • vHSM Telemetry Parameters
      • vHSM Agent
        • Agent Configuration
      • vHSM Proxy
        • Proxy Configuration
    • Get Started
      • Start the Vault server
      • MariaDB root admin password provisioning on Azure DCXas_v5 VM
    • Supported Cloud Configurations
  • Tutorials
    • Deploying the vhsm Container on an EC2 Instance
    • CLI quickstart
    • vHSM Agent quickstart
    • vHSM Proxy quickstart
    • Passing vHSM secrets using ConfigMaps
    • Provisioning MariaDB Password on Azure DCXas_v5 VM
    • Registering a buckypaper plugin
    • Monitoring vHSM with Grafana
  • Integration with Utimaco SecurityServer
    • Integrate enclaive vHSM with Utimaco HSM
  • API
    • Auth
    • Default
    • Secrets
    • System
    • Identity
    • Models
  • vHSM CLI
    • Server and Infrastructure Management
      • vhsm server
      • vhsm proxy
      • vhsm monitor
      • vhsm status
      • vhsm agent
    • Secret Management
      • vhsm read
      • vhsm write
      • vhsm delete
      • vhsm list
      • vhsm secrets
        • vhsm secrets enable
        • vhsm secrets disable
        • vhsm secrets list
        • vhsm secrets move
        • vhsm secrets tune
      • vhsm unwrap
    • Configuration and Management
      • vhsm plugin
        • vhsm plugin info
        • vhsm plugin deregister
        • vhsm plugin list
        • vhsm plugin register
        • vhsm plugin reload
        • vhsm plugin reload-status
      • vhsm namespace
      • vhsm operator
      • vhsm print
      • vhsm path-help
      • vhsm lease
    • Auditing and Debugging
      • vhsm audit
      • vhsm debug
    • Attestation
    • Security and Encryption
      • vhsm pki
        • vhsm pki health-check
        • vhsm pki issue
        • vhsm pki list-intermediates
        • vhsm pki reissue
        • vhsm pki verify-sign
      • vhsm transit
      • vhsm ssh
      • vhsm transform
    • Authentication and Authorization
      • vhsm login
      • vhsm auth
      • vhsm token
      • vhsm policy
    • Storage and Data Mangement
      • vhsm kv
      • vhsm patch
    • vhsm version
      • vhsm version-history
  • Troubleshooting
    • CA Validity Period
    • CRL Validity Period
    • Root Certificate Issued Non-CA Leaves
    • Role Allows Implicit Localhost Issuance
    • Role Allows Glob-Based Wildcard Issuance
    • Performance Impact
    • Accessibility of Audit Information
    • Allow If-Modified-Since Requests
    • Auto-Tidy Disabled
    • Tidy Hasn't Run
    • Too Many Certificates
    • Enable ACME Issuance
    • ACME Response Headers Configuration
  • Resources
    • Community
    • GitHub
    • Youtube
    • CCx101 wiki
Powered by GitBook
On this page

Was this helpful?

  1. Documentation

Supported Cloud Configurations

PreviousMariaDB root admin password provisioning on Azure DCXas_v5 VMNextTutorials

Last updated 9 months ago

Was this helpful?

The table below shows confidential compute workload configurations implemented by supported cloud service.

AWS supports AMD SEV-SNP-based confidential computing.

Size
vCPU
Memory (GiB)
Instance Storage (GB)
Network Bandwidth (Gbps)
EBS Bandwidth (Gbps)

m6a.large

2

8

EBS-Only

Up to 12.5

Up to 10

m6a.xlarge

4

16

EBS-Only

Up to 12.5

Up to 10

m6a.2xlarge

8

32

EBS-Only

Up to 12.5

Up to 10

m6a.4xlarge

16

64

EBS-Only

Up to 12.5

Up to 10

m6a.8xlarge

32

128

EBS-Only

12.5

10

c6a.large

2

4

EBS-Only

Up to 12.5

Up to 10

c6a.xlarge

4

8

EBS-Only

Up to 12.5

Up to 10

c6a.2xlarge

8

16

EBS-Only

Up to 12.5

Up to 10

c6a.4xlarge

16

32

EBS-Only

Up to 12.5

Up to 10

c6a.8xlarge

32

64

EBS-Only

12.5

10

c6a.12xlarge

48

96

EBS-Only

18.75

15

c6a.16xlarge

64

128

EBS-Only

25

20

r6a.large

2

16

EBS-Only

Up to 12.5

Up to 10

r6a.xlarge

4

32

EBS-Only

Up to 12.5

Up to 10

r6a.2xlarge

8

64

EBS-Only

Up to 12.5

Up to 10

r6a.4xlarge

16

128

EBS-Only

Up to 12.5

Up to 10

For more information, check:

Azure supports Intel-SGX-based, Intel-TDX-based, and AMD SEV-SNP-based confidential computing.

Confidential VMs support the following VM sizes:

  • Intel SGX support at DCsv2, DCsv3, and DCdsv3

  • General Purpose without local disk: DCasv5-series (AMD SEV-SNP), DCesv5-series (Intel TDX)

  • General Purpose with local disk: DCadsv5-series (AMD SEV-SNP), DCedsv5-series (Intel TDX)

  • Memory Optimized without local disk: ECasv5-series (AMD SEV-SNP), ECesv5-series (Intel TDX)

  • Memory Optimized with local disk: ECadsv5-series (AMD SEV-SNP), ECedsv5-series (Intel TDX)

Intel SGX

Size
Physical Cores
Memory GiB
Temp storage (SSD) GiB
Max data disks
Max NICs
EPC Memory MiB

DC1s_v2

1

4

50

1

1

28

DC2s_v2

2

8

100

2

1

56

DC4s_v2

4

16

200

4

1

112

DC8_v2

8

32

400

8

1

168

Size
Physical Cores
Memory GB
Temp storage (SSD) GiB
Max data disks
Max NICs
EPC Memory GiB

DC1s_v3

1

8

Remote Storage Only

4

2

4

DC2s_v3

2

16

Remote Storage Only

8

2

8

DC4s_v3

4

32

Remote Storage Only

16

4

16

DC8s_v3

8

64

Remote Storage Only

32

8

32

DC16s_v3

16

128

Remote Storage Only

32

8

64

DC24s_v3

24

192

Remote Storage Only

32

8

128

DC32s_v3

32

256

Remote Storage Only

32

8

192

DC48s_v3

48

384

Remote Storage Only

32

8

256

Size
Physical Cores
Memory GB
Temp storage (SSD) GiB
Max data disks
Max NICs
EPC Memory GiB

DC1ds_v3

1

8

75

4

2

4

DC2ds_v3

2

16

150

8

2

8

DC4ds_v3

4

32

300

16

4

16

DC8ds_v3

8

64

600

32

8

32

DC16ds_v3

16

128

1200

32

8

64

DC24ds_v3

24

192

1800

32

8

128

DC32ds_v3

32

256

2400

32

8

192

DC48ds_v3

48

384

2400

32

8

256

AMD SEV-SNP

Size
vCPU
Memory: GiB
Temp storage (SSD) GiB
Max data disks
Max uncached disk throughput: IOPS/MBps
Max NICs
Max network bandwidth (Mbps)

DC2as_v5

2

8

Remote Storage Only

4

3750/82

2

3000

DC4as_v5

4

16

Remote Storage Only

8

6400/144

2

5000

DC8as_v5

8

32

Remote Storage Only

16

12800/200

4

5000

DC16as_v5

16

64

Remote Storage Only

32

25600/384

4

10000

DC32as_v5

32

128

Remote Storage Only

32

51200/768

8

12500

DC48as_v5

48

192

Remote Storage Only

32

76800/1152

8

15000

DC64as_v5

64

256

Remote Storage Only

32

80000/1200

8

20000

DC96as_v5

96

384

Remote Storage Only

32

80000/1600

8

20000

Size
vCPU
Memory: GiB
Temp storage (SSD) GiB
Max data disks
Max temp storage throughput: IOPS/MBps
Max uncached disk throughput: IOPS/MBps
Max NICs
Max network bandwidth (Mbps)

DC2ads_v5

2

8

75

4

9000 / 125

3750/82

2

3000

DC4ads_v5

4

16

150

8

19000 / 250

6400/144

2

5000

DC8ads_v5

8

32

300

16

38000 / 500

12800/200

4

5000

DC16ads_v5

16

64

600

32

75000 / 1000

25600/384

4

10000

DC32ads_v5

32

128

1200

32

150000 / 2000

51200/768

8

12500

DC48ads_v5

48

192

1800

32

225000 / 3000

76800/1152

8

15000

DC64ads_v5

64

256

2400

32

300000 / 4000

80000/1200

8

20000

DC96ads_v5

96

384

3600

32

450000 / 4000

80000/1600

8

20000

Size
vCPU
Memory: GiB
Temp storage (SSD) GiB
Max data disks
Max uncached disk throughput: IOPS/MBps
Max NICs
Max network bandwidth (Mbps)

EC2as_v5

2

16

Remote Storage Only

4

3750/82

2

3000

EC4as_v5

4

32

Remote Storage Only

8

6400/144

2

5000

EC8as_v5

8

64

Remote Storage Only

16

12800/200

4

5000

EC16as_v5

16

128

Remote Storage Only

32

25600/384

4

10000

EC20as_v5

20

160

Remote Storage Only

32

32000/480

8

10000

EC32as_v5

32

256

Remote Storage Only

32

51200/768

8

12500

EC48as_v5

48

384

Remote Storage Only

32

76800/1152

8

15000

EC64as_v5

64

512

Remote Storage Only

32

80000/1200

8

20000

EC96as_v5

96

672

Remote Storage Only

32

80000/1600

8

20000

Size
vCPU
Memory: GiB
Temp storage (SSD) GiB
Max data disks
Max temp storage throughput: IOPS/MBps
Max uncached disk throughput: IOPS/MBps
Max NICs
Max network bandwidth (Mbps)

EC2ads_v5

2

16

75

4

9000 / 125

3750/82

2

3000

EC4ads_v5

4

32

150

8

19000 / 250

6400/144

2

5000

EC8ads_v5

8

64

300

16

38000 / 500

12800/200

4

5000

EC16ads_v5

16

128

600

32

75000 / 1000

25600/384

4

10000

EC20ads_v5

20

160

750

32

94000 / 1250

32000/480

8

10000

EC32ads_v5

32

256

1200

32

150000 / 2000

51200/768

8

12500

EC48ads_v5

48

384

1800

32

225000 / 3000

76800/1152

8

15000

EC64ads_v5

64

512

2400

32

300000 / 4000

80000/1200

8

20000

EC96ads_v5

96

672

3600

32

450000 / 4000

80000/1600

8

20000

Intel TDX

Size
vCPU
RAM (GiB)
Temp storage (SSD) GiB
Max data disks
Max temp disk throughput IOPS/MBps
Max uncached disk throughput IOPS/MBps
Max burst uncached disk throughput: IOPS/MBps
Max NICs
Max Network Bandwidth (Mbps)

DC2es_v5

2

8

RS*

4

N/A

3750/80

10000/1200

2

3000

DC4es_v5

4

16

RS*

8

N/A

6400/140

20000/1200

2

5000

DC8es_v5

8

32

RS*

16

N/A

12800/300

20000/1200

4

5000

DC16es_v5

16

64

RS*

32

N/A

25600/600

40000/1200

8

10000

DC32es_v5

32

128

RS*

32

N/A

51200/860

80000/2000

8

12500

DC48es_v5

48

192

RS*

32

N/A

76800/1320

80000/3000

8

15000

DC64es_v5

64

256

RS*

32

N/A

80000/1740

80000/3000

8

20000

DC96es_v5

96

384

RS*

32

N/A

80000/2600

120000/4000

8

30000

Size
vCPU
RAM (GiB)
Temp storage (SSD) GiB
Max data disks
Max temp disk throughput IOPS/MBps
Max uncached disk throughput IOPS/MBps
Max burst uncached disk throughput: IOPS/MBps
Max NICs
Max Network Bandwidth (Mbps)

DC2eds_v5

2

8

47

4

9300/100

3750/80

10000/1200

2

3000

DC4eds_v5

4

16

105

8

19500/200

6400/140

20000/1200

2

5000

DC8eds_v5

8

32

227

16

38900/500

12800/300

20000/1200

4

5000

DC16eds_v5

16

64

463

32

76700/1000

25600/600

40000/1200

8

10000

DC32eds_v5

32

128

935

32

153200/2000

51200/860

80000/2000

8

12500

DC48eds_v5

48

192

1407

32

229700/3000

76800/1320

80000/3000

8

15000

DC64eds_v5

64

256

2823

32

306200/4000

80000/1740

80000/3000

8

20000

DC96eds_v5

96

384

2823

32

459200/4000

80000/2600

120000/4000

8

30000

Size
vCPU
RAM (GiB)
Temp storage (SSD) GiB
Max data disks
Max temp disk throughput IOPS/MBps
Max uncached disk throughput IOPS/MBps
Max burst uncached disk throughput: IOPS/MBps
Max NICs
Max Network Bandwidth (Mbps)

EC2es_v5

2

16

RS*

4

N/A

3750/80

10000/1200

2

3000

EC4es_v5

4

32

RS*

8

N/A

6400/140

20000/1200

2

5000

EC8es_v5

8

64

RS*

16

N/A

12800/300

20000/1200

4

5000

EC16es_v5

16

128

RS*

32

N/A

25600/600

40000/1200

8

10000

EC32es_v5

32

256

RS*

32

N/A

51200/860

80000/2000

8

12500

EC48es_v5

48

384

RS*

32

N/A

76800/1320

80000/3000

8

15000

EC64es_v5

64

512

RS*

32

N/A

80000/1740

80000/3000

8

20000

EC128es_v5

128

768

RS*

32

N/A

80000/2600

120000/4000

8

30000

Size
vCPU
RAM (GiB)
Temp storage (SSD) GiB
Max data disks
Max temp disk throughput IOPS/MBps
Max uncached disk throughput IOPS/MBps
Max burst uncached disk throughput: IOPS/MBps
Max NICs
Max Network Bandwidth (Mbps)

EC2eds_v5

2

16

47

4

9300/100

3750/80

10000/1200

2

3000

EC4eds_v5

4

32

105

8

19500/200

6400/140

20000/1200

2

5000

EC8eds_v5

8

64

227

16

38900/500

12800/300

20000/1200

4

5000

EC16eds_v5

16

128

463

32

76700/1000

25600/600

40000/1200

8

10000

EC32eds_v5

32

256

935

32

153200/2000

51200/860

80000/2000

8

12500

EC48eds_v5

48

384

1407

32

229700/3000

76800/1320

80000/3000

8

15000

EC64eds_v5

64

512

2823

32

306200/4000

80000/1740

80000/3000

8

20000

EC128eds_v5

128

768

2832

32

459200/4000

80000/2600

120000/4000

8

30000

For more information, check:

GCP supports AMD SEV-SNP-based confidential computing.

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier 1 egress bandwidth (Gbps)

n2-standard-2

2

8

10

N/A

n2-standard-4

4

16

10

N/A

n2-standard-8

8

32

16

N/A

n2-standard-16

16

64

32

N/A

n2-standard-32

32

128

32

50

n2-standard-48

48

192

32

50

n2-standard-64

64

256

32

75

n2-standard-80

80

320

32

100

n2-standard-96

96

384

32

100

n2-standard-128

128

512

32

100

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier 1 egress bandwidth (Gbps)

n2-highmem-2

2

16

10

N/A

n2-highmem-4

4

32

10

N/A

n2-highmem-8

8

64

16

N/A

n2-highmem-16

16

128

32

N/A

n2-highmem-32

32

256

32

50

n2-highmem-48

48

384

32

50

n2-highmem-64

64

512

32

75

n2-highmem-80

80

640

32

100

n2-highmem-96

96

768

32

100

n2-highmem-128

128

864

32

100

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier 1 egress bandwidth (Gbps)

n2-highcpu-2

2

2

10

N/A

n2-highcpu-4

4

4

10

N/A

n2-highcpu-8

8

8

16

N/A

n2-highcpu-16

16

16

32

N/A

n2-highcpu-32

32

32

32

50

n2-highcpu-48

48

48

32

50

n2-highcpu-64

64

64

32

75

n2-highcpu-80

80

80

32

100

n2-highcpu-96

96

96

32

100

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier_1 egress bandwidth (Gbps)

c2d-standard-2

2

8

10

N/A

c2d-standard-4

4

16

10

N/A

c2d-standard-8

8

32

16

N/A

c2d-standard-16

16

64

32

N/A

c2d-standard-32

32

128

32

50

c2d-standard-56

56

224

32

50

c2d-standard-112

112

448

32

100

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier_1 egress bandwidth (Gbps)

c2d-highcpu-2

2

4

10

N/A

c2d-highcpu-4

4

8

10

N/A

c2d-highcpu-8

8

16

16

N/A

c2d-highcpu-16

16

32

32

N/A

c2d-highcpu-32

32

64

32

50

c2d-highcpu-56

56

112

32

50

c2d-highcpu-112

112

224

32

100

Machine types
vCPUs
Memory (GB)
Default egress bandwidth (Gbps)
Tier_1 egress bandwidth (Gbps)#

c2d-highmem-2

2

16

10

N/A

c2d-highmem-4

4

32

10

N/A

c2d-highmem-8

8

64

16

N/A

c2d-highmem-16

16

128

32

N/A

c2d-highmem-32

32

256

32

50

c2d-highmem-56

56

448

32

50

c2d-highmem-112

112

896

32

100

For more information, check:

Kraud supports AMD SEV-SNP-based confidential computing. For more information, check:

Requirements - Amazon Elastic Compute CloudAmazon Elastic Compute Cloud
Azure confidential computing productsMicrosoftLearn
Supported operating systems and machine types  |  Confidential VM  |  Google CloudGoogle Cloud
Confidential Containers - Kraud Cloud
Logo
Logo
Logo
Logo