CONFIDENTIAL COMPUTING ENVIRONMENT FOR SERVICE MESH ON A NETWORK INTERFACE DEVICE
Examples described herein relate to a executing a service mesh in a trust domain in a network interface device and executing one or more services in a second trust domain in one or more devices. In some examples, the network interface device is configured to determine trust domain capabilities of the network interface device and provide the trust domain capabilities based on a query.
1 . A non-transitory computer-readable medium, comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:
execute a service mesh in a trust domain in a network interface device and
execute one or more services in a second trust domain in one or more devices.
2 . The computer-readable medium of claim 1 , comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:
configure the network interface device to determine trust domain capabilities of the network interface device and provide the trust domain capabilities based on a query.
3 . The computer-readable medium of claim 1 , wherein the network interface device comprises one or more of: a network interface controller (NIC), a remote direct memory access (RDMA)-enabled NIC, SmartNIC, router, switch, forwarding element, infrastructure processing unit (IPU), or data processing unit (DPU).
4 . The computer-readable medium of claim 1 , wherein the one or more devices comprise one or more of: central processing unit (CPU), graphics processing unit (GPU), XPU, accelerator, storage, or memory.
5 . The computer-readable medium of claim 1 , wherein the trust domain is to provide data and executable code isolation and data isolation from one or more processes outside of the trust domain.
6 . The computer-readable medium of claim 1 , comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:
provide encrypted communications between the one or more services executing in the second trust domain and the service mesh executing in the trust domain.
7 . The computer-readable medium of claim 1 , wherein an orchestrator is to create the trust domain and the second trust domain.
8 . The computer-readable medium of claim 1 , wherein an orchestrator is to deploy execution of the service mesh in the trust domain and the one or more services in the second trust domain.
9 . The computer-readable medium of claim 1 , comprising instructions stored thereon, that if executed by one or more processors, cause the one or more processors to:
attest the trust domain prior to execution of the service mesh in the trust domain and
attest the second trust domain prior to execution of the one or more services in the trust second domain.
10 . A method comprising:
executing a service mesh in a trust domain in a network interface device and
executing one or more services in a second trust domain in one or more devices.
11 . The method of claim 10 , wherein the network interface device comprises one or more of: a network interface controller (NIC), a remote direct memory access (RDMA)-enabled NIC, SmartNIC, router, switch, forwarding element, infrastructure processing unit (IPU), or data processing unit (DPU).
12 . The method of claim 10 , wherein the one or more devices comprise one or more of: central processing unit (CPU), graphics processing unit (GPU), accelerator, storage, or memory.
13 . The method of claim 10 , wherein the trust domain is to provide data and executable code isolation and data isolation from one or more processes outside of the trust domain.
14 . The method of claim 10 , comprising:
providing encrypted communications between the one or more services executing in the second trust domain and the service mesh executing in the trust domain.
15 . The method of claim 10 , comprising:
an orchestrator creating the trust domain and the second trust domain.
16 . The method of claim 10 , comprising:
an orchestrator attesting the trust domain prior to execution of the service mesh in the trust domain and
an orchestrator attesting the second trust domain prior to execution of the one or more services in the trust second domain.
17 . An apparatus comprising:
a disaggregated composite compute node comprising:
a network interface device to execute a service mesh in a trust domain and
one or more devices to execute one or more services in a second trust domain.
18 . The apparatus of claim 17 , wherein the network interface device comprises one or more of: a network interface controller (NIC), a remote direct memory access (RDMA)-enabled NIC, SmartNIC, router, switch, forwarding element, infrastructure processing unit (IPU), or data processing unit (DPU).
19 . The apparatus of claim 17 , wherein the one or more devices comprise one or more of: central processing unit (CPU), graphics processing unit (GPU), XPU, accelerator, storage, or memory.
20 . The apparatus of claim 17 , wherein the trust domain is to provide data and executable code isolation and data isolation from one or more processes outside of the trust domain.
21 . The apparatus of claim 17 , comprising an interconnect to provide encrypted communications between the one or more services executing in the second trust domain and the service mesh executing in the trust domain.