aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Data
  • Platforms

Expanding Google Cloud’s Confidential Computing Portfolio

  • aster.cloud
  • September 10, 2020
  • 4 minute read

However you use Google Cloud services, your data is your data. Our layered approach to security proactively protects your data and gives you control on your terms. In fact, at Google we believe the future of computing will increasingly shift to private, encrypted services where users can be confident that their data is not being exposed to cloud providers or their own insiders. Confidential Computing makes this future possible by keeping data encrypted in memory, and elsewhere outside the CPU, while it is being processed.

In July, on the opening day of Google Cloud Next ‘20: OnAir, we announced the beta availability of Confidential VMs, the first product in our Confidential Computing portfolio. Today, we’re expanding our Google Cloud Confidential Computing portfolio and delivering on our vision with two announcements:


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

  • First, Confidential GKE Nodes, the second product in our confidential computing portfolio, will soon be available in beta, starting with the GKE 1.18 release. This gives organizations additional options for confidential workloads when they want to utilize Kubernetes clusters with Google Kubernetes Engine (GKE).
  • We’re also making Confidential VMs generally available. This capability will be available to all Google Cloud customers in the coming weeks and will include new features we’ve added during beta.

 

Bringing confidential computing to your container workloads

As our customers move to modernize existing applications and build cloud-native ones, GKE is increasingly the foundation they use. Application modernization also presents the opportunity to modernize security, and as we looked at building our Confidential Computing portfolio, we wanted to deliver a new level of confidentiality and portability for containerized workloads. Google Cloud Confidential GKE Nodes are built on the same technology foundation as Confidential VMs, and allow you to keep data encrypted in memory with a node-specific dedicated key that’s generated and managed by the AMD EPYC processor.Under the hood, Confidential GKE Nodes will enable you to configure your GKE cluster to only deploy node pools with Confidential VM capabilities underneath. Clusters with Confidential GKE Nodes enabled will automatically enforce the use of Confidential VMs for all your worker nodes. GKE Confidential Nodes will use hardware memory encryption powered by the AMD Secure Encrypted Virtualization feature used by AMD EPYC™ processors, which means that your workloads running on the confidential nodes will be encrypted in-use.

Read More  Use Your Favorite DevOps And Security Solutions With GKE Autopilot Out Of The Box

Stay tuned for more on Confidential GKE Nodes next month.

 

Confidential VMs expanding to generally availability

In Google Cloud, we employ a variety of isolation and sandboxing techniques to help make our multi-tenant architecture secure. Confidential VMs take this to the next level, using memory encryption to further isolate workloads and tenants from each other, and from the cloud infrastructure. It provides an easy-to-use option, for both lift-and-shift and newly created workloads, to protect the memory of workloads in Google Compute Engine.”The ability to encrypt sensitive data in the cloud whether at rest, in transit, or now, in use through confidential computing is very compelling for enterprises,” said Raphaël de Cormis, VP Digital Factory, Thales. “Quite simply, the fact that Google Cloud’s Confidential VMs offer this level of isolation in an easy-to-use package will help our customers achieve compliance and privacy in a seamless and cost-efficient manner.”

Confidential VMs offer high performance for the most demanding computational tasks, while keeping VM memory encrypted with a dedicated per-VM instance key that is generated and managed by the AMD secure processor embedded within AMD EPYC processors. Confidential VMs can scale to 240 vCPUs and 896 GiB memory, and can be used without significant performance degradation.

“We’re excited to see the advanced security feature within AMD EPYC processors, Secure Encrypted Virtualization, expand from Google Cloud Confidential VMs, to Confidential GKE Nodes,” said Raghu Nambiar, corporate vice president, Data Center Ecosystem, AMD. “With AMD EPYC processors and Google Cloud’s Confidential Computing portfolio we are helping to keep customers’ data secure so they can feel confident that they can easily move their applications to the cloud.”

Read More  How Wayfair Is Modernizing, One Database At A Time

Building on the underlying technology, we’re releasing new capabilities for Confidential VMs:

1. Audit reports for compliance. Audit reports now include detailed logs about the integrity of the AMD Secure Processor Firmware that’s responsible for key generation in Confidential VM instances. We establish an integrity baseline when you first launch your VM and match against it whenever a VM is relaunched. You can also set custom actions or alerts based on these logs.

Audit reports.gif
Audit reports

2. New policy controls for confidential computing resources. You can now use the IAM Org Policy to define specific access privileges for Confidential VMs. You can also disable any non-confidential VMs running in your project. Once this policy is applied, any attempt to start a non-confidential VM within that project will fail. As we expand the services that offer Confidential Computing, these IAM policies will help you stay in control over which Confidential Computing resources you want to enable in your project/folder or organization.

Policy controls for Confidential VMs.png
Policy controls for Confidential VMs

3. Integration with other enforcement mechanisms. You can use a combination of Shared VPCs, organization policy constraints, and firewall rules to ensure Confidential VMs can only interact with other Confidential VMs, even when these VMs live inside different projects. Furthermore, you can use VPC Service Controls to define a perimeter of GCP resources for your Confidential VMs. For example, you can configure Google Cloud Storage buckets to be accessible only by Confidential VMs service accounts.

4. Sharing secrets securely with Confidential VMs. While using a Confidential VM, you may need to process a sensitive file that is encrypted with an external key. In this situation, the file ciphertext and the encryption key need to be shared with the Confidential VM. To make sure that sharing of such secrets is done securely, Confidential VMs can use the virtual Trusted Platform Module (vTPM), and with the go-tpm open source library you can use APIs to bind your secrets to the vTPM of your Confidential VM.

 

A game-changing technology

Transformational technologies solve problems that make our lives better. Confidential computing can be a catalyst to transform the way organizations process data in the cloud while preserving confidentiality and privacy. We can’t wait to see the possibilities this technology will open up for your organization. You can start using Confidential VMs today and sign-up to be notified when the Confidential GKE Nodes beta is available.

Sunil Potti
General Manager/VP of Engineering, Cloud Security
Eyal Manor
General Manager/VP of Engineering, Application Modernization Platform

For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • GKE
  • Google Cloud
  • Google Cloud Next ’20
  • Google Kubernetes Engine
  • Kubernetes
  • Virtual Machine
You May Also Like
Data center
View Post
  • Data
  • Public Cloud

Data Sovereignty in Spain. It’s Not Just About the Law, It’s About Efficiency

  • June 3, 2026
View Post
  • Data
  • Platforms
  • Technology

Scaling cloud and AI: Microsoft Azure’s commitment to Europe’s digital future

  • May 11, 2026
View Post
  • Data

Streamline read scalability with Cloud SQL autoscaling read pools

  • March 23, 2026
View Post
  • Data
  • Platforms
  • Public Cloud

PayPal’s historically large data migration is the foundation for its gen AI innovation

  • March 4, 2026
View Post
  • Platforms
  • Technology

Microsoft Sovereign Cloud adds governance, productivity and support for large AI models securely running even when completely disconnected 

  • March 3, 2026
View Post
  • Data
  • Technology

3 obstacles to agentic AI adoption and how to overcome them

  • December 22, 2025
Getting things done makes her feel amazing
View Post
  • Computing
  • Data
  • Featured
  • Learning
  • Tech
  • Technology

Nurturing Minds in the Digital Revolution

  • April 25, 2025
View Post
  • Data
  • Engineering

Hiding in Plain Site: Attackers Sneaking Malware into Images on Websites

  • January 16, 2025

Stay Connected!
LATEST
  • 1
    IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average
    • July 29, 2026
  • 2
    Accelerating the frontiers of scientific discovery: Google’s $40M commitment to the Genesis Mission
    • July 26, 2026
  • 3
    3 Questions: Neural transparency and the future of AI design
    • July 17, 2026
  • 4
    Intel Invests €5 Billion to Expand Manufacturing in Europe
    • July 13, 2026
  • 5
    IBM and Red Hat Expand Lightwell with New Offerings to Build the Trust Infrastructure for AI-Era Open Source
    • July 8, 2026
  • 6
    When I Was Young
    • July 4, 2026
  • 7
    The Fastest AI Fried Chicken In The World
    • June 29, 2026
  • 8
    Zed Approves | How to Stay Cool in Extreme Heat
    • June 29, 2026
  • 9
    The AI investment surge hasn’t produced the expected results yet. That could change in 2026
    • June 26, 2026
  • 10
    Zed Approves | It’s Prime Day 2026! Time to Upgrade Your World Cup Viewing Setup and Beat the Heat
    • June 25, 2026
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    Zed Approves | The Best Prime Day PC Deals: Top Gaming Rigs, Workstations, and Everyday Laptops
    • June 24, 2026
  • neon-cart 2
    Zed Approves: How to Gear Up for GTA 6 This Amazon Prime Day (2026 Quick Guide)
    • June 22, 2026
  • zedreviews-valerion 3
    Father’s Day Outdoors – Build Dad the Ultimate Backyard Watch Party
    • June 20, 2026
  • zedreviews-fathers-day-50830 4
    Father’s Day Outdoors, Round Two – Gear for the Action, the Tailgate, and Beating the Heat
    • June 20, 2026
  • zedreviews-fathers-day-2147684744 5
    The Ultimate Father’s Day Gift Guide – Home Entertainment Upgrades Dad Actually Wants
    • June 20, 2026
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.