mirror of
https://github.com/cloud-hypervisor/cloud-hypervisor.git
synced 2026-08-05 02:19:16 +00:00
docs: update SEV-SNP backend support
Remove the stale MSHV-only wording now that the docs and CVM test path cover KVM SEV-SNP with IGVM stage0 and fw_cfg [0, 1]. [0]: https://github.com/cloud-hypervisor/cloud-hypervisor/pull/7942 [1]: https://github.com/cloud-hypervisor/cloud-hypervisor/pull/8347 On-behalf-of: SAP philipp.schuster@sap.com Signed-off-by: Philipp Schuster <philipp.schuster@cyberus-technology.de>
This commit is contained in:
committed by
Bo Chen
parent
013981b649
commit
2e62081bec
@@ -1,9 +1,5 @@
|
||||
# AMD SEV-SNP
|
||||
|
||||
### WARNING
|
||||
|
||||
This feature is currently only supported on MSHV.
|
||||
|
||||
AMD Secure Encrypted Virtualization & Secure Nested Paging (SEV-SNP) is an AMD
|
||||
technology designed to add strong memory integrity protection to help prevent
|
||||
malicious hypervisor-based attacks like data replay, memory-remapping and more
|
||||
@@ -18,7 +14,8 @@ links:
|
||||
A machine with AMD SEV-SNP support which is enabled in the BIOS is required.
|
||||
|
||||
On the Cloud Hypervisor side, all you need is to build the project with the
|
||||
`sev_snp` feature enabled:
|
||||
`sev_snp` feature enabled. This enables the MSHV and IGVM support that is
|
||||
needed by the default SEV-SNP build:
|
||||
|
||||
```bash
|
||||
cargo build --no-default-features --features "sev_snp"
|
||||
@@ -27,6 +24,13 @@ cargo build --no-default-features --features "sev_snp"
|
||||
**Note**
|
||||
Please note that `sev_snp` cannot be enabled in conjunction with the `tdx` feature flag.
|
||||
|
||||
SEV-SNP is also supported on KVM with an IGVM stage0 image and a guest kernel
|
||||
provided through `fw_cfg`. Build that configuration with:
|
||||
|
||||
```bash
|
||||
cargo build --no-default-features --features "kvm,igvm,sev_snp,fw_cfg"
|
||||
```
|
||||
|
||||
You can run a SEV-SNP VM using the following command:
|
||||
|
||||
```bash
|
||||
@@ -37,4 +41,4 @@ You can run a SEV-SNP VM using the following command:
|
||||
--disk path=ubuntu.img
|
||||
```
|
||||
|
||||
For more information related to Microsoft Hypervisor, please see [mshv.md](mshv.md)
|
||||
For more information related to Microsoft Hypervisor, please see [mshv.md](mshv.md).
|
||||
|
||||
Reference in New Issue
Block a user