Google has added Kubernetes support to Confidential Computing

TL;DR: Now you can run Kubernetes on Confidential VMs by Google.

Google has added Kubernetes support to Confidential Computing

Google today (08.09.2020, translator's note) at the event Cloud Next OnAir announced the expansion of its product line with the launch of a new service.

Confidential GKE nodes add more privacy to workloads running in Kubernetes. The first product named Confidential VMs, launched in July, is now publicly available to everyone.

Confidential Computing is a new technology that enables data to be kept encrypted during processing. This is the last link in the data encryption chain since cloud service providers already encrypt data at input and output. Until recently, it was necessary to decrypt data during processing, and many experts see this as a clear gap in data encryption.

Google's Confidential Computing initiative is based on collaboration with the Confidential Computing Consortium, an industry group aimed at promoting the concept of Trusted Execution Environments (TEEs). A TEE is a secure part of the processor where loaded data and code are encrypted, meaning that access to this information by other parts of the same processor is impossible.

Google's Confidential VMs run on N2D virtual machines powered by AMD's second-generation EPYC processors, utilizing Secure Encrypted Virtualization technology, which allows isolation of virtual machines from the hypervisor on which they operate. There is a guarantee that data remains encrypted regardless of its usage: workloads, analytics, requests for training models for artificial intelligence. These virtual machines are designed to meet the needs of any company working with sensitive data in regulated areas, such as the banking sector.

Perhaps more urgent is the announcement about the upcoming beta testing of Confidential GKE nodes, which, according to Google, will be featured in the upcoming release 1.18 Google Kubernetes Engine (GKE). GKE is a managed, production-ready environment for running containers that host parts of modern applications, which can run in multiple computing environments. Kubernetes is an open-source orchestration tool used to manage these containers.

Adding Confidential GKE nodes provides greater confidentiality when launching GKE clusters. With the introduction of a new product in the Confidential Computing line, we aimed to ensure a new level
of confidentiality and portability for containerized workloads. Confidential GKE nodes from Google are built on the same technology as Confidential VMs, allowing you to encrypt data in memory with a unique encryption key for each node, created and managed by the AMD EPYC processor. These nodes will utilize hardware-based memory encryption based on AMD's SEV function, meaning that your workloads running on these nodes will be encrypted while they're in operation.

Sunil Potti and Eyal Manor, cloud technology engineers, Google

On Confidential GKE nodes, clients can configure GKE clusters such that node pools will be launched on Confidential VMs. Simply put, any workloads running on these nodes will be encrypted during data processing.

Many enterprises require even more confidentiality when using public cloud services than for on-premises workloads run on their own infrastructure, which is necessary to protect against malicious actors. Google Cloud, by expanding its range of Confidential Computing, raises this bar, providing users with the ability to ensure confidentiality for GKE clusters. Considering the popularity of Kubernetes, this is a key step forward for the industry, giving companies greater opportunities for the secure deployment of next-generation applications in the public cloud.

Holger Mueller, analyst at Constellation Research.

N.B. Our company is launching an updated intensive course from September 28 to 30 Kubernetes Base for those who are new to Kubernetes but want to get acquainted with it and start working. Following this event, from October 14 to 16, we are launching an updated Kubernetes Mega for experienced Kubernetes users who need to be aware of all the latest practical solutions in working with the latest versions of Kubernetes and potential pitfalls. During this course, Kubernetes Mega we will discuss the nuances of installing and configuring a production-ready cluster (the-not-so-easy-way), as well as the mechanisms for ensuring application security and fault tolerance.

In addition, Google announced that its Confidential VMs will gain new features as they become publicly available starting today. For example, audit reports have been introduced, containing detailed logs of the integrity checks for the AMD Secure Processor used to create keys for each instance of Confidential VMs.

There are also more controls for setting specific access rights, and Google has added the capability to disable any non-confidential virtual machine on a designated project. Additionally, Google integrates Confidential VMs with other secrecy mechanisms to ensure security.

You can use a combination of shared VPCs with firewall rules and restrictions in organizational policies to ensure that Confidential VMs can exchange data with other Confidential VMs, even if they operate in different projects. Furthermore, you can use VPC Service Controls to define the resource scope in GCP for your Confidential VMs.

Sunil Potti and Eyal Manor

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster