Enabling confidential VMs
To enable confidential VMs on Azure for your Red Hat OpenShift Container Platform cluster, you can configure the install-config.yaml file before deployment. Apply the settings to control plane nodes, compute nodes, or all nodes as needed.
You can use confidential VMs with the following VM sizes:
-
DCasv5-series
-
DCadsv5-series
-
ECasv5-series
-
ECadsv5-series
-
DCesv5-series
-
DCedsv5-series
-
ECesv5-series
-
ECedsv5-series
-
NCCads_H100_v5
|
|
Confidential VMs are currently not supported on 64-bit ARM architectures. |
-
You have created an
install-config.yamlfile.
-
Edit the
install-config.yamlfile before deploying your cluster:-
Enable confidential VMs only on control plane by adding the following stanza:
controlPlane: platform: azure: settings: securityType: ConfidentialVM confidentialVM: uefiSettings: secureBoot: Enabled virtualizedTrustedPlatformModule: Enabled osDisk: securityProfile: securityEncryptionType: VMGuestStateOnly -
Enable confidential VMs only on compute nodes by adding the following stanza:
compute: platform: azure: settings: securityType: ConfidentialVM confidentialVM: uefiSettings: secureBoot: Enabled virtualizedTrustedPlatformModule: Enabled osDisk: securityProfile: securityEncryptionType: VMGuestStateOnly -
Enable confidential VMs on all nodes by adding the following stanza:
platform: azure: defaultMachinePlatform: settings: securityType: ConfidentialVM confidentialVM: uefiSettings: secureBoot: Enabled virtualizedTrustedPlatformModule: Enabled osDisk: securityProfile: securityEncryptionType: VMGuestStateOnly
-