How We Built Cages: Building Enclaves Easily
Blog post from Evervault
Evervault developed Cages to simplify the deployment of Trusted Execution Environments (Secure Enclaves) for developers, focusing on maintaining the integrity of Platform Configuration Registers (PCRs) and eliminating the need for users to trust Evervault. By allowing users to build Cages locally using an open-source CLI, the company ensures transparency and security, as the data-plane is the only addition to the Enclave, and PCR values come directly from the Nitro CLI. The process involves converting Docker containers into Enclave Image Files (EIFs) using AWS's Nitro CLI and overcoming challenges like running the Nitro CLI on non-Linux systems, managing the complexity of installing runtime components in arbitrary Dockerfiles, and ensuring reproducibility of builds. Evervault's approach includes using tools like Kaniko and BuildKit to achieve reproducible builds by standardizing timestamps, thus ensuring consistent PCRs across different builds. The development of Cages emphasizes making Enclave deployment accessible and reliable while maintaining data security and integrity.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.