Confidential Compute trên AWS EKS với AMD SEV-SNP, Kata Containers và Trustee Attestation
Triển khai Workload Confidential Compute trên AWS EKS với AMD SEV-SNP, Kata Containers và Trustee
Các mô hình bảo mật Zero-Trust hiện đại yêu cầu bảo vệ không chỉ dữ liệu tĩnh (data-at-rest) và dữ liệu đang truyền (data-in-transit), mà đặc biệt là dữ liệu đang xử lý (data-in-use). Confidential Computing giải quyết thách thức này bằng cách thực thi các workload bên trong Môi trường Thực thi Đáng tin cậy (Trusted Execution Environment - TEE) được cách ly bằng phần cứng. Hướng dẫn kỹ thuật này chi tiết cách triển khai giải pháp Confidential Computing toàn diện trên Amazon EKS sử dụng bộ vi xử lý AMD EPYC thế hệ thứ 3 với AMD SEV-SNP, runtime Kata Containers và kiến trúc xác thực Trustee.
1. Kiến trúc Tổng quan và Mô hình Hiểm họa
Trong kiến trúc Kubernetes tiêu chuẩn, nhà cung cấp hạ tầng cloud, hypervisor và các tiến trình OS bị chiếm quyền điều khiển trên node đều có khả năng kiểm tra bộ nhớ của các container đang chạy. Confidential Containers (CoCo) thay đổi ranh giới tin cậy (trust boundary) bằng cách cách ly các Pod vào trong những MicroVM được mã hóa bằng phần cứng nhờ AMD SEV-SNP.
Các Nguyên tắc Bảo mật Chính của AMD SEV-SNP:
- Mã hóa Bộ nhớ: Các khóa mã hóa AES-128/256 được quản lý hoàn toàn bởi AMD Secure Processor (AMD-SP).
- Bảng Ánh xạ Ngược (Reverse Map Table - RMP): Ngăn chặn các cuộc tấn công thay đổi ánh xạ bộ nhớ, write-aliasing và can thiệp bộ nhớ từ hypervisor.
- Xác thực Từ xa (Remote Attestation): Cung cấp bằng chứng mã hóa về trạng thái phần cứng, measurement của firmware và pod trước khi cấp phát khóa giải mã.
Kiến trúc dựa trên 4 lớp thành phần cốt lõi:
- AWS Nitro System & EC2 (AMD SEV-SNP): Các instance Bare metal hoặc Nitro (ví dụ: dòng
m6a.metalhoặcm6a) chạy CPU AMD EPYC hỗ trợ SEV-SNP. - Kata Containers Confidential Runtime: Lớp MicroVM wrapper chạy các guest kernel với bộ nhớ cách ly mã hóa.
- Kiến trúc Trustee Attestation: Bao gồm Key Broker Service (KBS), Attestation Service (AS) và Reference Value Provider Service (RVPS).
- Confidential Data Hub (CDH): Chạy bên trong guest utility VM để lấy token xác thực và secret từ Trustee.
2. Khởi tạo Node EKS hỗ trợ AMD SEV-SNP
Để hỗ trợ các workload mã hóa phần cứng, các worker node trên EKS phải sử dụng kernel hỗ trợ SEV-SNP và cấu hình tham số ảo hóa chính xác. Dưới đây là cấu hình Terraform để khởi tạo một EKS Node Group với instance m6a.metal cùng user-data tùy chỉnh.
# main.tf - AWS EKS Node Group hỗ trợ AMD SEV-SNP
resource "aws_eks_node_group" "confidential_nodes" {
cluster_name = aws_eks_cluster.main.name
node_group_name = "eks-amd-sev-snp-nodes"
node_role_arn = aws_iam_role.node_role.arn
subnet_ids = module.vpc.private_subnets
scaling_config {
desired_size = 2
max_size = 5
min_size = 1
}
ami_type = "CUSTOM"
instance_types = ["m6a.metal"]
launch_template {
name = aws_launch_template.sev_snp_template.name
version = aws_launch_template.sev_snp_template.latest_version
}
}
resource "aws_launch_template" "sev_snp_template" {
name_prefix = "eks-sev-snp-"
image_id = data.aws_ami.eks_custom_amzn2023.id
instance_type = "m6a.metal"
user_data = base64encode(<<-EOF
#!/bin/bash
set -o errexit
set -o pipefail
# Bật các Kernel Parameter cho AMD SEV-SNP
grubby --update-kernel=ALL --args="mem_encrypt=on kvm_amd.sev=1 kvm_amd.sev_snp=1"
# Phân quyền thiết bị SEV
echo 'KERNEL=="sev", MODE="0660", GROUP="kvm"' > /etc/udev/rules.d/80-sev.rules
# Chạy script bootstrap của EKS
/etc/eks/bootstrap.sh ${aws_eks_cluster.main.name}
EOF
)
metadata_options {
http_endpoint = "enabled"
http_tokens = "required" # Bắt buộc IMDSv2
http_put_response_hop_limit = 1
}
}3. Cài đặt Kata Containers và RuntimeClass SEV-SNP
Sau khi các node đã sẵn sàng, tiến hành cài đặt Confidential Containers Operator để thiết lập Kata runtime và đăng ký RuntimeClass kata-sev-snp.
# runtime-class-sev-snp.yaml
apiVersion: node.k8s.io/v1
kind: RuntimeClass
metadata:
name: kata-sev-snp
handler: kata-sev-snp
overhead:
podFixed:
cpu: "250m"
memory: "350Mi"
scheduling:
nodeSelector:
feature.node.kubernetes.io/amd-sev-snp: "true"
---
# coco-operator-config.yaml
apiVersion: confidentialcontainers.org/v1alpha1
kind: CcRuntime
metadata:
name: ccruntime-sample
namespace: conf-containers-system
spec:
ccNodeSelector:
matchLabels:
node.kubernetes.io/instance-type: m6a.metal
config:
defaultRuntimeClassName: kata-sev-snp
payloads:
- quay.io/confidential-containers/runtime-payload:v0.8.0
runtimeClasses:
- name: kata-sev-snp
snapshotter: overlayfs
hypervisor: qemu-sev-snp
launchSecurity:
type: amd-sev-snp
cbitpos: 51
reducedPhysBits: 1
policy: "0x30000" # Cấu hình chính sách bảo mật SEV-SNP
4. Cấu hình Trustee Key Management và Attestation Service
Trustee hoạt động như một hệ thống quản lý khóa Key Broker Service (KBS) và Attestation Service (AS). Nó chịu trách nhiệm kiểm tra chứng thư phần cứng (chuỗi VCEK cấp bởi AMD) và thông số measurement của Pod trước khi bàn giao khóa giải mã.
# trustee-kbs-config.yaml
apiVersion: v1
kind: ConfigMap
metadata:
name: kbs-config
namespace: trustee-system
data:
kbs-config.json: |
{
"attestation_token_config": {
"attestation_token_type": "Ear",
"expiration_time": 3600
},
"repository": {
"type": "LocalFs",
"dir_path": "/opt/trustee/kbs/repository"
},
"as_addr": "http://attestation-service.trustee-system.svc.cluster.local:50004"
}
---
# opa-policy.rego lưu trong Attestation Service
apiVersion: v1
kind: ConfigMap
metadata:
name: attestation-policy
namespace: trustee-system
data:
policy.rego: |
package policy
default allow = false
# Launch measurement chuẩn được tính toán từ quy trình build an toàn
expected_launch_digest := "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
allow {
input.tee == "sev-snp"
input.sev_snp.policy == 393216 # 0x60000
input.sev_snp.launch_digest == expected_launch_digest
input.sev_snp.vcek_cert_chain_valid == true
}5. Triển khai Confidential Workloads trên EKS
Khi Kata runtime và Trustee đã hoạt động, chúng ta triển khai một Confidential Pod. Trong quá trình khởi tạo, Confidential Data Hub (CDH) bên trong microVM sẽ gửi báo cáo chứng thực phần cứng SEV-SNP đến Trustee để lấy khóa giải mã secret.
# confidential-workload.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: confidential-analytics-engine
namespace: secure-workloads
spec:
replicas: 1
selector:
matchLabels:
app: confidential-analytics
template:
metadata:
labels:
app: confidential-analytics
annotations:
io.katacontainers.config.hypervisor.machine_type: "q35"
io.katacontainers.config.hypervisor.kernel_params: "agent.trustee_kbs_addr=http://kbs.trustee-system.svc.cluster.local:8080"
spec:
runtimeClassName: kata-sev-snp
containers:
- name: analytics-core
image: my-registry.internal/secure-analytics:v1.2.0
imagePullPolicy: Always
env:
- name: TRUSTEE_KBS_URI
value: "http://kbs.trustee-system.svc.cluster.local:8080"
- name: SECRET_RESOURCE_PATH
value: "kbs:///default/db-credentials/prod-key"
resources:
limits:
cpu: "4"
memory: "8Gi"
requests:
cpu: "2"
memory: "4Gi"
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL6. Kiểm tra Thực tế và Quy trình Vận hành
Để đảm bảo cơ chế mã hóa bộ nhớ và chứng thực đang hoạt động chính xác, thực hiện các lệnh kiểm tra phần cứng từ máy chủ worker node và xem log của Trustee KBS.
Lệnh kiểm tra phần cứng & Attestation:
# Kiểm tra trạng thái AMD SEV-SNP trên EKS Node
dmesg | grep -i -E "sev|snp"
# Kết quả mong đợi: cpm: SEV-SNP supported, kvm: AMD SEV-SNP enabled
# Kiểm tra tình trạng phần cứng AMD qua công cụ sevctl
sevctl ok
# Kết quả mong đợi:
# [✔] AMD CPU supports SEV-SNP
# [✔] SEV-SNP driver loaded
# [✔] Guest firmware installed
# [✔] Hardware identity validated against AMD RPK
# Theo dõi log Trustee KBS khi khởi chạy Pod
kubectl logs -n trustee-system deployment/trustee-kbs -f | grep "Attestation Result"
# Mẫu log output:
# {"timestamp":"2023-10-24T10:15:30Z","level":"INFO","event":"Attestation successful","tee":"sev-snp","digest_matched":true}7. Đánh giá Rủi ro Bảo mật & Khuyến nghị Vận hành
| Rủi ro Bảo mật | Mô tả Bề mặt Tấn công | Chiến lược Giải quyết |
|---|---|---|
| Đọc trộm bộ nhớ từ Hypervisor | OS chủ hoặc Quản trị viên Cloud đọc RAM | Sử dụng mã hóa RAM bằng phần cứng AES qua AMD SEV-SNP Reverse Map Table (RMP). |
| Xác thực Giả mạo (Spoofed Attestation) | Guest độc hại gửi bằng chứng measurement giả | Kiểm tra chuỗi chứng thực AMD VCEK đối chiếu với AMD Root Key (ARK) thông qua Trustee AS. |
| Container Image không Mã hóa | Lộ nội dung image trên Registry công cộng | Bắt buộc mã hóa OCI Image (CoCo Guest sẽ tự kéo và giải mã image bên trong MicroVM). |
| Rò rỉ IMDS Metadata | Guest VM truy vấn IAM Role của EKS Node | Bắt buộc bật IMDSv2 với hop count = 1 để chặn Pod Kata truy cập Metadata của Node chủ. |
