For the complete documentation index, see llms.txt. This page is also available as Markdown.

Overview

Confidential VM follows a shared responsibility model where IONOS CLOUD secures the underlying platform infrastructure, while you maintain exclusive control over everything within the TEE. For information on what falls outside the responsibility of IONOS CLOUD, see Security boundaries.

How a Confidential VM differs from a standard VM

Feature

Standard VM

Confidential VM

Data in memory

Unencrypted; hypervisor-readable

Hardware-encrypted; hardware-isolated and protected. Memory contents are cryptographically unreadable.

Trust model

Policy-based ("we won't look")

Hardware-enforced ("we can't look")

Security guarantee

Contractual commitment

Cryptographic proof

Operator access

Administrative path exists

Physically impossible

Important: Confidential VMs, which run in an IONOS CLOUD EU data center, in the Frankfurt-East de/fra/2 region, are not subject to the US CLOUD Act. This provides a hardware-enforced sovereignty guarantee for regulated workloads.

How IONOS CLOUD isolates your workload

The following illustration shows a Confidential VM isolated within AMD SEV-SNP Trusted Execution Environment, with the host OS, hypervisor, and cloud admin outside the trust boundary:

  • Host-side actors (Host OS / hypervisor, Cloud / infra admin) operate outside the trust boundary; they see only ciphertext and cannot inject, inspect, or modify the VM state.

  • External attack vectors (Memory scraper, diagnostic tools) are isolated at the hardware boundary without access path into the TEE or its workloads.

  • IONOS CLOUD is equally excluded; the AMD CPU generates and holds encryption keys internally. For more information, see Security and trust model.

Diagram showing a Confidential VM isolated inside an AMD SEV-SNP Trusted Execution Environment, with the host OS, hypervisor, and cloud admin outside the trust boundary
Confidential VM on an IONOS CLOUD TEE

How do I set up a Confidential VM?

The following five steps describe the complete lifecycle from image preparation to an operating a Confidential VM.

  1. Prepare your image: Build a custom Linux image that includes the LAUNCH_ARTIFACTS partition. This partition must contain a launch-config.json, and the expected measurement. The initrd boots before the OS. If you are using attestation, embed the attestation client within the initrd. For more information, see Prepare a confidential image.

  2. Deploy your attestation service: (Optional). Deploy and configure your attestation service in a location reachable from the Confidential VM's launch network. Register the measurement policy the service will use to verify attestation report. For the IONOS CLOUD open-source reference implementation, see SNPGuard. For more information, see Attest a Confidential VM and What is a measurement and how is it computed?.

  3. Create a Confidential VM: Use the IONOS CLOUD API to create a Confidential VM at a Confidential VM-capable location. Specify the launch volume built from your image and the required vCPU and memory configuration. For more information, see Create a Confidential VM.

  4. Confidential VM starts: The initrd runs before the OS. If you deployed an attestation service, the attestation client embedded in the initrd contacts it, verification runs, the Volume Master Key (VMK) is released, and the root filesystem is decrypted. Without attestation, the initrd is responsible for unlocking the root filesystem on its own. For more information, see The startup process.

  5. Operate: Monitor attestation events and handle planned maintenance.

Last updated

Was this helpful?