AWS Nitro Enclaves are little "sidecar" isolated VMs with no network access or storage that you can create and communicate to only from an EC2 VM to eg store secrets and keys in, do crypto. https://aws.amazon.com/ec2/nitro/nitro-enclaves/ … they also have attestation. Currently in preview.
-
-
Replying to @justincormack
Sounds just right for putting unikernels in the enclaves. They claim enclaves won't have network connectivity, so how would they communicate back to EC2 VM, something like VM sockets?
1 reply 0 retweets 2 likes -
Replying to @botwhytho
Some sort of socket/ring buffer but dont have details yet
2 replies 0 retweets 2 likes
Replying to @justincormack @botwhytho
There's a vsock between the parent instance and the enclave attached to it.
0 replies
1 retweet
6 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.