What Is QingTian Enclave?
- QingTian Enclave instances are secure and isolated virtual machines (VMs) using the QingTian architecture. The instance that has the ownership of QingTian Enclave instances is called the parent instance. QingTian Enclave instances are completely independent VMs and have no persistent storage, interactive access, or external networking. They communicate with the parent instance through a secure local channel, which is called vsock. Even the root user of the parent instance cannot access or SSH into QingTian Enclave instances.
- The QingTian Hypervisor isolates the vCPUs and memory of QingTian Enclave instances from the parent instance to provide an isolated environment and greatly reduce the attack surface area. QingTian Enclave helps you protect sensitive core data and applications and enhance the security of your services in QingTian Enclave.
- QingTian Enclave also supports attestation that allows you to verify the identity of QingTian Enclave instances. Huawei Cloud Key Management Service (KMS) provides built-in support for attestation to only allow applications in specific QingTian Enclave instances to be able to call KMS APIs for sensitive data processing.
Constraints
QingTian Enclave instances have the following constraints.
Name |
Constraints |
---|---|
Parent instance (primary VM) |
|
QingTian Enclave instances (secondary VMs) |
|
For details about isolating vCPUs and memory, see Resource Isolation.
The relationship between QingTian Enclave instances and their parent instance are as follows:
- A maximum of two QingTian Enclave instances can be created from a parent instance.
- QingTian Enclaves instances cannot share the same physical core with their parent instance.
- QingTian Enclave instances are running only when the parent instance is running. If the parent instance is stopped or terminated, QingTian Enclave instances are also stopped or terminated.
- Resources (vCPUs and memory) of QingTian Enclave instances come from the parent instance. The memory range must be a continuous physical range aligned by 2 MiB/1 GiB.
You also need to note the following:
- The parent instance that supports QingTian Enclave is C7t.
- QingTian Enclave is available in the following regions: CN North-Beijing4, CN East-Shanghai1, and CN South-Guangzhou.
- If your services running in the QingTian Enclave instances are terminated unexpectedly, you need to manually run the services again.
- By default, 1 GiB hugepages are configured for QingTian Enclave instances, with 1 GiB of memory and 2 vCPUs.
Billing
QingTian Enclave is free during the open beta test (OBT). You only need to pay for the ECSs you purchase.
Related Services
QingTian Enclave integrates with the following Huawei Cloud services:
- KMS
Key Management Service (KMS) is a core service provided by Huawei Cloud Data Encryption Workshop (DEW). KMS is a highly available cloud service that helps users to create, store, manage, and audit keys. KMS uses Hardware Security Modules (HSMs) to protect keys and can be integrated with multiple Huawei Cloud services. Additionally, you can develop customized encryption applications using KMS.
- IAM
The Identity and Access Management (IAM) provides permissions management to securely manage access to your Huawei Cloud services and resources.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot