Home / Companies / Evervault / Blog / Post Details
Content Deep Dive

How We Built Cages: Deploying to an Enclave

Blog post from Evervault

Post Details
Company
Date Published
Author
Dónal Tuohy
Word Count
1,343
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

Deploying a Cage, a secure enclave server, involves a multi-step process designed to streamline and secure operations in a production environment. The process begins with the architecture of a Cage, comprising a control plane, data plane, and user process, each playing distinct roles to ensure effective communication and processing within the enclave. The deployment process includes uploading an Enclave Image File (EIF) to the Evervault infrastructure, building a Docker image incorporating the EIF and control plane using Kaniko, and programmatic deployment through AWS Step Functions, which manage interdependent infrastructure components. Key elements such as EC2 Auto Scaling Groups, ECS Services, and AWS Cloudmap are utilized for high availability, efficient resource management, and seamless service discovery and routing. Throughout the deployment, status updates and observability features like logs and metrics provide insights into the Cage's performance and security, with weekly security patches ensuring the system remains up to date. This comprehensive approach aims to simplify the deployment of Trusted Execution Environments, offering a user-friendly interface and robust security features.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.